PT-2026-82370 · Drupal · Address Suggestion
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal Address Suggestion versions 0.0.0 through 1.0.25
Description
Improper neutralization of input during web page generation allows for Cross-Site Scripting (XSS). The Address Suggestion module, which provides address autocomplete functionality via configured providers, fails to sufficiently sanitize the data returned by these providers. Exploitation requires an attacker to inject malicious content into the data returned by a configured address provider and a user to perform a search that triggers the malicious suggestion.
Recommendations
Update Drupal Address Suggestion to a version later than 1.0.25.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Address Suggestion