CVE-2018-7603
Last modified
CVE-2018-7603 is a vulnerability of currently unknown severity. In Drupal's 3rd party module search auto complete prior to versions 7.x-4.8 there is a Cross Site Scripting vulnerability. This Search Autocomplete module enables you to autocomplete textfield using data from your website (nodes, comments, etc.). EPSS estimates a 0.79% chance of exploitation in the next 30 days.
Description
In Drupal's 3rd party module search auto complete prior to versions 7.x-4.8 there is a Cross Site Scripting vulnerability. This Search Autocomplete module enables you to autocomplete textfield using data from your website (nodes, comments, etc.). The module doesn't sufficiently filter user-entered text among the autocompletion items leading to a Cross Site Scripting (XSS) vulnerability. This vulnerability can be exploited by any user allowed to create one of the autocompletion item, for instance, nodes, users, comments.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Search Autocomplete Project | Search Autocomplete | < 7.x-4.8 |
References
- https://www.drupal.org/sa-contrib-2018-070Patch, Vendor Advisory
- https://www.drupal.org/sa-contrib-2018-070Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7603?
How severe is CVE-2018-7603?
How do I fix CVE-2018-7603?
Are you affected by CVE-2018-7603?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
