CVE-2026-13242
בינונית 6.5
תיאור (מקור, אנגלית)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. This issue affects Geolocation Field versions: from 0.0.0 to 3.15.0.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-17/8/2026
- CWE
- CWE-89
מוצרים מושפעים
dopry: geolocation field
קישורים
- https://www.drupal.org/sa-contrib-2026-062 Vendor Advisory