Impact
The vulnerability is a cross‑site scripting flaw, classified as CWE-79, within the Drupal Screenshot module. The advisory indicates that all versions of the module are affected, but it does not detail the specific attack vector. A cross‑site scripting vulnerability allows an attacker to inject malicious scripts into pages served by the module, potentially giving them the ability to steal session data or perform actions on behalf of users. Because the module functions through the web interface, any exploitation could compromise the confidentiality and integrity of the Drupal site and its users.
Affected Systems
Affected systems are Drupal installations that have the Screenshot module enabled. The advisory does not specify exact version numbers; therefore, all releases of the Screenshot module are considered vulnerable until a patch is released.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating limited known exploitation activity but not ruling out future attacks. The CVSS score of 7.3 indicates moderate to high risk. The advisory does not provide a patch or update date, and no official fix has been issued. The likely attack vector is inferred to be remote exploitation via HTTP requests to the module’s endpoints. Administrators should monitor for newly discovered exploits and consider disabling the module until a fix is released.
OpenCVE Enrichment