Impact
Insertion of Sensitive Information Into Sent Data is a vulnerability that enables an attacker to forcefully retrieve data that should not be exposed. The weakness lies in how the DXPR Builder handles user requests, allowing an unauthorized user to craft requests that trigger the application to send back private or confidential information. This flaw is a classic information‑disclosure weakness and corresponds to CWE‑201.
Affected Systems
Drupal provides the DXPR Builder: The Best Editing (AI) Experience for Drupal, which is vulnerable in all releases from version 0.0.0 through 2.8.1 inclusive. Any installation of the component in this version range is susceptible to exploitation.
Risk and Exploitability
The exploit is likely to be performed via a forceful browsing attack, where an attacker submits crafted input to the component to read back protected data. The CVSS score is 5.3, indicating a moderate severity level, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, so no public exploitation data is presently reported. However, because the flaw permits disclosure of sensitive information without authentication, the impact on confidentiality is still high. Authorities should treat this as a moderate‑to‑critical risk until an official fix is deployed.
OpenCVE Enrichment