—
DRUPAL-CONTRIB-2025-116
Details
This module provides the ability to convert any entity form into a simple multi-step form.
The module doesn’t sufficiently filter certain user-provided text leading to a cross-site scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission “administer node form display”.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/simple_multistep
Introduced in:
0Fixed in: 2.0.0Upgrade drupal/simple_multistep to 2.0.0 or newer (ecosystem packagist:https://packages.drupal.org/8).