PT-2026-56661 · Drupal · Location Selector

·

CVE-2026-15081

·

Published

2026-07-08

·

Updated

2026-08-06

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Location Selector versions 0.0.0 through 1.3.0
Description An SQL injection issue exists in the Location Selector module, which provides a Views filter for selecting location values. A specific Views filter fails to sufficiently sanitize values derived from user input, allowing for the improper neutralization of special elements used in an SQL command. This issue is mitigated if no View using the affected filter is configured to accept user input.
Recommendations Update Location Selector to a version later than 1.3.0.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15081
DRUPAL-CONTRIB-2026-072

Affected Products

Location Selector