Impact
Drupal Entity Browser contains an improper neutralization of input during web page generation that allows attackers to embed malicious scripts in stored data. This stored XSS flaw (CWE‑79) enables the script to execute automatically in the web browser whenever a user views the affected entity, potentially compromising the security of the site’s front end.
Affected Systems
The affected product is the Drupal Entity Browser module for Drupal. All releases from 0.0.0 through 2.16.0 are vulnerable. Site administrators should verify whether these versions are installed and plan for an upgrade.
Risk and Exploitability
The CVSS score is 4.8, the EPSS score is not available, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that attackers can inject arbitrary scripts via the Entity Browser’s content input interface, and those scripts will be stored and served to users viewing the entity. This attack vector requires no elevated privileges and can be executed by unauthenticated visitors who can submit content through the module.
OpenCVE Enrichment