PT-2026-63536 · Drupal+1 · Search Api Autocomplete+1
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Search API Autocomplete versions 0.0.0 through 1.12.0
Description
Improper neutralization of input during web page generation allows Reflected Cross-site Scripting (XSS), a flaw where malicious scripts are injected into a web page and reflected back to the user. The issue exists in a test script accessible to anonymous users that fails to sufficiently validate user input. This is partially mitigated if the web server is configured to hide warning messages from users.
Recommendations
Update Search API Autocomplete to a version later than 1.12.0.
As a temporary mitigation, configure the web server to disable the display of warning messages to users.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Search Api Autocomplete
Drupal Search Autocomplete