Impact
Drupal Siteimprove Analytics implements a component that fails to properly neutralize user supplied input during web page generation, resulting in a Cross‑Site Scripting vulnerability (CWE‑79). This flaw permits an attacker to insert arbitrary JavaScript that will run in the browsers of any user who accesses the affected content. The impact is confined to the client side; a victim’s session is not exposed by default, nor is there a statement that the vulnerability can be leveraged for cookie theft or session hijacking.
Affected Systems
Siteimprove Analytics for Drupal is affected. Versions from 0.0.0 through 2.0.1 contain the flaw, while any newer versions are considered safe.
Risk and Exploitability
The EPSS score of < 1 % indicates a very low but non‑zero likelihood of exploitation, and the issue is not listed in CISA’s KEV catalog. The CVSS score of 5.4 reflects moderate severity due to client‑side script execution risk. The likely attack vector involves injecting malicious scripts via user‑controllable inputs or data fields within the module; this inference is drawn from the description of improper input neutralization. Any visitor who loads affected pages could be exposed to the rendered payload.
OpenCVE Enrichment