PT-2026-52164 · Drupal+2 · Advanced Content Feedback+1
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal Advanced Content Feedback versions 0.0.0 through 2.8.0
Description
Stored Cross-site Scripting (XSS) occurs when the module fails to sufficiently sanitize administrator-configured response messages. Specifically, the "Yes response", "No response", and custom text for "No" answers can contain HTML or script markup that is emitted as raw HTML to site visitors. Exploitation requires the attacker to possess a role with the "administer admin feedback" permission.
Recommendations
Update Drupal Advanced Content Feedback to a version later than 2.8.0.
Restrict the "administer admin feedback" permission to only trusted users to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advanced Content Feedback
Drupal/Admin Feedback