Impact
A flaw in Drupal Slick Carousel allows the injection of arbitrary script into carousel content that is saved and subsequently visible to all users. The stored cross‑site scripting can lead to credential theft, session hijacking, or site defacement, and is classified as CWE‑79.
Affected Systems
Drupal Slick Carousel, versions from 0.0.0 up to and including 2.1.0.
Risk and Exploitability
The vulnerability can be exploited when an attacker is able to create or edit carousel items, a capability that typically requires authentication and appropriate content‑management permissions. Because the malicious script is stored, any subsequent page view by any visitor triggers its execution. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, so the historical exploitation probability is unknown. Nevertheless, the possibility of widespread client‑side compromise makes it a notable risk for sites using this module. The CVSS score of 6.1 indicates moderate severity.
OpenCVE Enrichment