{"id":"DRUPAL-CONTRIB-2025-117","details":"This module allows uploading a zip file and extracting its content in the public file directory to serve this content from a Drupal website.\n\nThese zip files may contain arbitrary HTML or SVG content that could allow cross-site scripting vulnerabilities. While this is an expected feature, the module does not sufficiently restrict this functionality to trusted users with a \"restricted access\" permission. Users without a restricted permission should not be able to inject arbitrary JavaScript.\n\nThis vulnerability is mitigated by the fact that an attacker must have a role with the permission *create [bundle] content* permission.","aliases":["CVE-2025-13979"],"modified":"2026-09-10T03:45:57.510819154Z","published":"2025-12-03T18:47:37Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2025-117"}],"affected":[{"package":{"name":"drupal/minisite","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/minisite?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.2"}],"database_specific":{"constraint":"\u003c3.0.2"}}],"database_specific":{"source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/minisite/DRUPAL-CONTRIB-2025-117.json","affected_versions":"\u003c3.0.2"}}],"schema_version":"1.9.0","credits":[{"name":"Pierre Rudloff (prudloff)","contact":["https://www.drupal.org/u/prudloff"]}]}