Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet SmartTag allows Cross-Site Scripting (XSS).This issue affects AT Internet SmartTag: from 0.0.0 before 1.0.1.
Published: 2026-02-04
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site Scripting
Action: Patch
AI Analysis

Impact

This vulnerability arises from improper neutralization of user input when generating a web page, allowing an attacker to inject malicious scripts into pages served by the Drupal AT Internet SmartTag module. The injected scripts execute in the context of the victim’s browser, potentially enabling session hijacking, credential theft, or defacement of the site. The weakness corresponds to CWE-79, which focuses on inadequate input filtering or output encoding.

Affected Systems

Drupal A.T. Internet SmartTag is affected from version 0.0.0 up to, but not including, 1.0.1. The module’s functionality applies to any Drupal site that has the SmartTag module installed within that version range.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild, and the vulnerability is not flagged in the CISA Known Exploit Vulnerabilities catalogue. Attackers would need to provide crafted input to the SmartTag module—most likely via exposed parameters or content fields—to trigger the XSS. Because the flaw occurs during page rendering, the impact is confined to users who visit the compromised pages; however, the presence of arbitrary script execution can be leveraged for broader attacks such as phishing or state‑changing requests.

Generated by OpenCVE AI on April 17, 2026 at 23:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Drupal AT Internet SmartTag to version 1.0.1 or later, which removes the XSS flaw
  • Validate and escape all user‑supplied input before it is rendered by the module, following best practices for web output encoding
  • If an update cannot be applied immediately, disable or uninstall the SmartTag module to eliminate the attack surface

Generated by OpenCVE AI on April 17, 2026 at 23:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 11 Feb 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Bordeaux-metropole
Bordeaux-metropole at Internet Smarttag
CPEs cpe:2.3:a:bordeaux-metropole:at_internet_smarttag:*:*:*:*:*:drupal:*:*
Vendors & Products Bordeaux-metropole
Bordeaux-metropole at Internet Smarttag

Fri, 06 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Feb 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal at Internet Smarttag
Vendors & Products Drupal
Drupal at Internet Smarttag

Wed, 04 Feb 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet SmartTag allows Cross-Site Scripting (XSS).This issue affects AT Internet SmartTag: from 0.0.0 before 1.0.1.
Title AT Internet SmartTag - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-003
Weaknesses CWE-79
References

Subscriptions

Bordeaux-metropole At Internet Smarttag
Drupal At Internet Smarttag
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-02-06T20:35:38.434Z

Reserved: 2026-01-14T16:52:30.774Z

Link: CVE-2026-0946

cve-icon Vulnrichment

Updated: 2026-02-06T20:35:34.895Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-04T21:15:58.907

Modified: 2026-02-11T19:19:34.760

Link: CVE-2026-0946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T23:15:30Z

Weaknesses