Impact
Improper Neutralization of Input During Web Page Generation (CWE‑79) in Drupal Anti‑Spam by CleanTalk allows reflected cross‑site scripting. This vulnerability can potentially allow malicious scripts to be executed in a victim's browser when input is reflected without proper sanitization.
Affected Systems
All installations of the Drupal Anti‑Spam by CleanTalk module from version 0.0.0 through 9.7.1 are affected. Any Drupal site using this module is potentially at risk.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate risk. Because the flaw permits reflected cross‑site scripting, attackers could inject malicious input that is echoed back to users. The EPSS score of less than 1% suggests that exploitation is not widespread. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment