Impact
The issue is a classic Cross‑Site Scripting (XSS) flaw caused by insufficient sanitization of user input during web page generation in Drupal Canvas. An attacker who can submit or influence content displayed by Drupal Canvas can inject malicious JavaScript that executes in the browsers of visitors to those pages. This client‑side execution can result in defacement, theft of session cookies, or complete session hijacking.
Affected Systems
The vulnerability affects Drupal Canvas versions 0.0.0 through 1.4.2, 1.5.0 through 1.5.2, 1.6.0 through 1.6.1, and 1.7.0 through 1.7.1. Only those releases listed are impacted; other releases are outside the scope of this advisory.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity level with client‑side impact only. The EPSS score of less than 1% demonstrates a low likelihood of exploitation at the time of this analysis, and the vulnerability is not included in the CISA KEV catalog, implying no known widespread exploitation. Exploitation requires an attacker to supply crafted input that a user subsequently views; no direct remote code execution or privilege escalation is possible solely from this flaw.
OpenCVE Enrichment