Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet Piano Analytics allows Cross-Site Scripting (XSS).This issue affects AT Internet Piano Analytics: from 0.0.0 before 1.0.1, from 2.0.0 before 2.3.1.
Published: 2026-02-04
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

The vulnerability is an instance of improper neutralization of user input during web page generation, resulting in a Cross‑Site Scripting (XSS) flaw in the AT Internet Piano Analytics module for Drupal. The flaw allows an attacker to inject arbitrary client‑side code that will execute when the affected content is rendered in a user’s browser. No explicit downstream consequences such as credential theft or session hijacking are documented in the official description, so the exact impact depends on how the module reflects user supplied data to page output.

Affected Systems

Drupal AT Internet Piano Analytics versions prior to 1.0.1 (from 0.0.0 up to, but not including, 1.0.1) and prior to 2.3.1 (from 2.0.0 up to, but not including, 2.3.1) are affected. The vulnerability applies to the module as deployed on any Drupal site that uses these versions.

Risk and Exploitability

The CVSS base score of 4.8 indicates a moderate severity, and the EPSS score of less than 1% signifies a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly defined in the advisory; based on the nature of XSS, it is inferred that an attacker could exploit the flaw by submitting malicious input through a form field or by manipulating a URL parameter that is subsequently rendered, but such conditions are not specified in the official text.

Generated by OpenCVE AI on April 18, 2026 at 13:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AT Internet Piano Analytics module to version 1.0.1 or later, or 2.3.1 or later, to remove the XSS flaw.
  • If an immediate upgrade is not feasible, implement input filtering or deploy content‑security‑policy headers to block execution of injected scripts.
  • After applying the recommended changes, monitor site traffic for unexpected script activity and verify that the module no longer reflects unsanitized input.

Generated by OpenCVE AI on April 18, 2026 at 13:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 11 Feb 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Bordeaux-metropole
Bordeaux-metropole at Internet Piano Analytics
CPEs cpe:2.3:a:bordeaux-metropole:at_internet_piano_analytics:*:*:*:*:*:drupal:*:*
Vendors & Products Bordeaux-metropole
Bordeaux-metropole at Internet Piano Analytics

Thu, 05 Feb 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal at Internet Piano Analytics
Vendors & Products Drupal
Drupal at Internet Piano Analytics

Wed, 04 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Feb 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet Piano Analytics allows Cross-Site Scripting (XSS).This issue affects AT Internet Piano Analytics: from 0.0.0 before 1.0.1, from 2.0.0 before 2.3.1.
Title AT Internet Piano Analytics - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-004
Weaknesses CWE-79
References

Subscriptions

Bordeaux-metropole At Internet Piano Analytics
Drupal At Internet Piano Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-02-04T21:24:09.075Z

Reserved: 2026-01-14T16:52:31.950Z

Link: CVE-2026-0947

cve-icon Vulnrichment

Updated: 2026-02-04T21:23:59.427Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-04T21:15:59.030

Modified: 2026-02-11T19:19:26.493

Link: CVE-2026-0947

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T13:45:45Z

Weaknesses