Impact
The vulnerability is an improper neutralization of input during web page generation, classified as Cross‑Site Scripting. It allows an attacker to inject malicious script into pages rendered by the Drupal Address Suggestion module, with the injected code executing in the victim’s browser. The weakness is in OWASP CWE‑79.
Affected Systems
This flaw exists in Drupal Address Suggestion versions from 0.0.0 up to 1.0.25, inclusive. All installations of the module within that range are vulnerable. The issue does not affect other Drupal core components directly, only the Address Suggestion add‑on.
Risk and Exploitability
The CVSS score is 4.8, classifying the vulnerability as moderate. The advisory labels the issue as moderately critical, indicating a significant risk to user confidentiality and integrity. EPSS is not available, so the exact likelihood of exploitation is uncertain; however, XSS flaws are routinely abused, and since the vulnerability allows arbitrary script execution, it can be leveraged by attackers with a likely web‑based attack vector. The vulnerability is not listed in CISA’s KEV catalog, meaning there is no confirmed exploitation in the wild reported at this time.
OpenCVE Enrichment