Impact
An improperly neutralized user input in the Drupal Canvas module lets attackers inject malicious code into web pages rendered for other users. The flaw is a classic XSS (CWE-79), allowing script execution in victims’ browsers.
Affected Systems
The Drupal Canvas module for the Drupal content‑management system is affected. Vulnerable releases are 0.0.0 through 1.4.2, 1.5.0 through 1.5.2, 1.6.0 through 1.6.1, and 1.7.0 through 1.7.1.
Risk and Exploitability
The CVSS base score of 6.1 indicates moderate severity; based on the description, it is inferred that attacks may be launched by users who can submit content to the Canvas component, typically via normal content‑creation forms. The vulnerability allows malicious JavaScript to be injected into pages viewed by other users. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV database. Potential damage could include client‑side data theft or session hijacking, but these impacts were not explicitly stated in the CVE text. The likely attack vector deduced from the description is web‑based content submission, and any authenticated user with permission to enter content may trigger it.
OpenCVE Enrichment