Impact
Improper neutralization of input during web page generation in Drupal AI SEO/GEO Analyzer permits stored Cross‑Site Scripting. An attacker can embed malicious JavaScript that persists in the database and executes each time the affected page is displayed, potentially exposing sensitive data or enabling unauthorized actions within the victim’s browser context.
Affected Systems
The vulnerability affects the Drupal AI SEO/GEO Analyzer module for versions from 0.0.0 through 1.1.3 inclusive. Any installation running one of these versions should assess whether the module remains required.
Risk and Exploitability
The weakness is identified as CWE‑79 and carries a CVSS score of 5.4, indicating moderate severity. The EPSS score is less than 1%, suggesting a low exploitation likelihood at present, and the issue is not listed in CISA’s KEV catalog. Based on typical stored XSS scenarios, the likely attack vector involves submitting malicious input to the module’s data entry points, which is later rendered without proper sanitization.
OpenCVE Enrichment