5.4 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
35.3%
Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels.
drupalcode.org/project/search_api_sorts.git/commitdiff/f6cbf47
www.openwall.com/lists/oss-security/2013/01/25/4
drupal.org/node/1896756
drupal.org/node/1896782