Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. This issue affects Geolocation Field versions: from 0.0.0 to 3.15.0.
Published: 2026-07-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization defect in Drupal Ge statements into commands. This can enable read or write operations on the database, potentially exposing sensitive data or corrupting application state. The flaw represents a classic CWE‑89 injection weakness, compromising integrity and confidentiality of the underlying data store.

Affected Systems

Drupal Geolocation Field in all versions from 0.0.0 up to and including 3.15.0 is affected. The vulnerability resides in Drupal’s geolocation module and applies to any deployment that uses these module versions.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating that observed exploitation is rare at present. The CVSS score of 6.5 categorizes this vulnerability as medium severity, but because it is a SQL injection that does not require privileged access, the potential impact remains significant if an attacker can craft suitable input. The likely attack vector is via user‑controllable HTTP requests to pages processed by the Geolocation Field, is incorporated into database queries.

Generated by OpenCVE AI on July 29, 2026 at 09:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Drupal Geolocation Field to the latest release that resolves the injection flaw.
  • If the module is not required, disable or uninstall it to remove the attack surface.
  • Apply defensive input validation or a web application firewall to block malformed SQL characters in incoming requests.

Generated by OpenCVE AI on July 29, 2026 at 09:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal geolocation Field
Vendors & Products Drupal
Drupal geolocation Field

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. This issue affects Geolocation Field versions: from 0.0.0 to 3.15.0.
Title Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062
Weaknesses CWE-89
References

Subscriptions

Drupal Geolocation Field
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-13T16:05:20.863Z

Reserved: 2026-06-24T18:00:15.050Z

Link: CVE-2026-13242

cve-icon Vulnrichment

Updated: 2026-07-13T16:04:40.815Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T10:00:15Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')