Impact
An improper neutralization defect in Drupal Ge statements into commands. This can enable read or write operations on the database, potentially exposing sensitive data or corrupting application state. The flaw represents a classic CWE‑89 injection weakness, compromising integrity and confidentiality of the underlying data store.
Affected Systems
Drupal Geolocation Field in all versions from 0.0.0 up to and including 3.15.0 is affected. The vulnerability resides in Drupal’s geolocation module and applies to any deployment that uses these module versions.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating that observed exploitation is rare at present. The CVSS score of 6.5 categorizes this vulnerability as medium severity, but because it is a SQL injection that does not require privileged access, the potential impact remains significant if an attacker can craft suitable input. The likely attack vector is via user‑controllable HTTP requests to pages processed by the Geolocation Field, is incorporated into database queries.
OpenCVE Enrichment