Impact
Drupal Media Folders contains an improper neutralization of user input during web page generation, leading to a stored cross‑site scripting vulnerability. The flaw allows an attacker to inject malicious HTML or JavaScript that is saved in the media folder and rendered to other users, potentially executing arbitrary client‑side code when viewers access that content.
Affected Systems
The affected product is the Drupal Media Folders module, versions from 0.0.0 up to and including 1.0.8. Any installation running one of these versions without a later update is susceptible to the vulnerability.
Risk and Exploitability
EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no current widespread exploitation, but the risk remains high for sites where content editors can write or upload arbitrary media folder entries. Because the flaw is stored XSS, remote attackers need only convince a legitimate user or an editor to input malicious content, after which the stored code can run in the browsers of all visitors to that page.
OpenCVE Enrichment