CVE-2026-81167: Address Suggestion - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-103
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/Address Suggestionto a version that resolves this vulnerability.Fixed in 1.0.25Patch SA-CONTRIB-2026-103
Event History
Frequently Asked Questions
Which installations are affected?
Drupal Address Suggestion versions from 0.0.0 through 1.0.25 are affected.
What access and interaction are required for exploitation?
The CVSS vector indicates an attacker needs high privileges and requires user interaction. The attack can be performed over the network with low attack complexity.
What is the potential impact?
Successful exploitation may allow limited disclosure of information and limited modification of data. The impact can cross a security authority boundary, while availability impact is not indicated.