Impact
The Drupal Monster Menus module contains a stored cross‑site scripting flaw that permits attackers to inject JavaScript into menu entries. Classified as CWE‑79, the vulnerability causes arbitrary script execution in the context of any user who views the affected menu. The malicious code is stored and served with every page load.
Affected Systems
All installations of Drupal’s Monster Menus module from version 0.0.0 through 9.5.3 are affected. Any site using these versions without an update should be considered vulnerable.
Risk and Exploitability
The flaw is exploitable remotely by submitting crafted input into menu fields; the malicious content is stored and later served to visitors, allowing repeated exploitation without additional interaction. CVSS score 6.1 indicates moderate severity. EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The stored XSS nature means that any user who views the affected menu will have the malicious script executed in their browser.
OpenCVE Enrichment