View online: https://www.drupal.org/sa-contrib-2025-042
Project: Bootstrap Site Alert [1] Date: 2025-April-23 Security risk: *Moderately critical* 13 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:All [2] Vulnerability: Cross Site Scripting
Affected versions: <1.13.0 || >=3.0.0 <3.0.4 CVE IDs: CVE-2025-3901 Description: This module enables you to put a site wide bootstrap themed alert message on the top of every page.
The module doesn't sufficiently filter text input when leading to a possible XSS attacks.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer bootstrap site alerts".
Solution: Install the latest version:
* If you use the bootstrap_site_alert module 8.x-1.x, upgrade to bootstrap_site_alert 8.x-1.23. [3] * If you use the bootstrap_site_alerts module 3.0.x, upgrade to bootstrap_site_alert 3.0.4. [4]
Reported By: * Mitch Portier (arkener) [5] * Elijah Byrd (elibyrd) [6]
Fixed By: * Mitch Portier (arkener) [7] * Joseph Olstad (joseph.olstad) [8] * Ivo Van Geertruyen (mr.baileys) [9] of the Drupal Security Team
Coordinated By: * Greg Knaddison (greggles) [10] of the Drupal Security Team * Juraj Nemec (poker10) [11] of the Drupal Security Team
[1] https://www.drupal.org/project/bootstrap_site_alert [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/bootstrap_site_alert/releases/8.x-1.13 [4] https://www.drupal.org/project/bootstrap_site_alert/releases/3.0.4 [5] https://www.drupal.org/u/arkener [6] https://www.drupal.org/u/elibyrd [7] https://www.drupal.org/u/arkener [8] https://www.drupal.org/u/josepholstad [9] https://www.drupal.org/u/mrbaileys [10] https://www.drupal.org/u/greggles [11] https://www.drupal.org/u/poker10