CVE-2026-15081
גבוהה 7.4
תיאור (מקור, אנגלית)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0.
מדדים
- CVSS 3.1
-
7.4 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-17/8/2026
- CWE
- CWE-89
מוצרים מושפעים
handkerchief: location selector
קישורים
- https://www.drupal.org/sa-contrib-2026-072 Vendor Advisory