CVE Database
/

CVE-2018-7603

Back to search

CVE-2018-7603

Published: Jan 15, 2019

Modified: Sep 17, 2024

PUBLISHED

Description

In Drupal's 3rd party module search auto complete prior to versions 7.x-4.8 there is a Cross Site Scripting vulnerability. This Search Autocomplete module enables you to autocomplete textfield using data from your website (nodes, comments, etc.). The module doesn't sufficiently filter user-entered text among the autocompletion items leading to a Cross Site Scripting (XSS) vulnerability. This vulnerability can be exploited by any user allowed to create one of the autocompletion item, for instance, nodes, users, comments.

VendorProductVersions

Drupal

3rd party module - Search Autocomplete

affected
7.x-4.x - < 7.x-4.8

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now