Impact
The advisory identifies a vulnerability in the Drupal Powerful Surveys contributed module. The official description does not specify the nature, mechanism, or exact consequences of the flaw. As a result, the precise impact—whether it could lead to data exposure, arbitrary code execution, or denial of service—remains unknown.
Affected Systems
All installations of the Drupal Powerful Surveys module are affected. The advisory lists the affected versions as '*.*', indicating that every released build of the module could be vulnerable. The module is part of the Drupal ecosystem and is typically deployed via web interfaces exposed to external users.
Risk and Exploitability
The CVSS score is 5.7. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Because the module is unsupported, no official patch exists. The risk remains moderate, especially if the module is exposed to web traffic. The likely attack vector, inferred from typical Drupal module architecture, involves sending crafted requests to the module’s endpoints. Without a fix, attackers could potentially exploit the flaw remotely, though the exact conditions for exploitation are unclear.
OpenCVE Enrichment