Impact
Improper neutralization of input during web page generation in the Drupal AI component introduces a classic Cross‑Site Scripting weakness (CWE‑79). Based on the description, it is inferred that an attacker could embed malicious scripts into content that is rendered in user browsers. The flaw exists in module code that fails to escape user‑supplied data before output.
Affected Systems
Drupal AI (Artificial Intelligence) modules with versions from 0.0.0 through 1.2.17, from 1.3.0 to 1.3.8, and from 1.4.0 to 1.4.3 are affected. Any Drupal site that has installed or enabled the AI module within these release ranges is vulnerable. Versions newer than 1.4.3 are not listed as affected, but sites should verify by checking the module’s release notes or the official advisory.
Risk and Exploitability
The CVSS score of 6.1 classifies this vulnerability as Medium severity. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote. It is further inferred that the vulnerability could be exploited via a crafted input that is rendered by an authenticated or unauthenticated user. Based on the description, it is inferred that a successful exploitation would occur when a user visits a page containing the injected script, resulting in script execution in the victim’s browser context.
OpenCVE Enrichment