Impact
An improperly neutralized user input during page generation in Drupal Search API Autocomplete allows a reflected cross‐site scripting vulnerability. If an attacker supplies crafted data that is echoed back in the autocomplete suggestions, the browser will execute the injected script, enabling defacement, cookie theft, or session hijacking.
Affected Systems
Drupal Search API Autocomplete modules installed on a Drupal website are affected. All releases from the initial 0.0.0 to version 1.12.0 are vulnerable; any site running these versions is at risk.
Risk and Exploitability
The vulnerability is classified as moderately critical. The CVSS score is 6.1. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog. XSS is a well‐known attack that can be triggered via reflected payloads. Without an immediate patch, users face the possibility of arbitrary script execution when viewing autocomplete results. The attack is likely to be performed by sending malicious data in the query that triggers suggestions, which does not require administrator privileges but works against any authenticated or unauthenticated user who receives the injected response.
OpenCVE Enrichment