Miggo Logo

CVE-2025-12083: Drupal CivicTheme Design System allows Cross-Site Scripting (XSS)

6.1

CVSS Score
3.1

Basic Information

EPSS Score
0.07099%
Published
10/30/2025
Updated
10/30/2025
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
drupal/civicthemecomposer< 1.12.01.12.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

No analysis provided

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

Improp*r N*utr*liz*tion o* Input *urin* W** P*** **n*r*tion ('*ross-sit* S*riptin*') vuln*r**ility in *rup*l *ivi*T**m* **si*n Syst*m *llows *ross-Sit* S*riptin* (XSS). T*is issu* *****ts *ivi*T**m* **si*n Syst*m: *rom *.*.* ***or* *.**.*.

Reasoning

No *n*lysis provi***