SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-13242

MEDIUM · CVSS 6.5 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The vulnerability in the Geolocation Field module for Drupal allows for SQL Injection due to improper neutralization of special elements in SQL commands, affecting versions from 0.0.0 to 3.15.0. Successful exploitation could enable attackers to manipulate database queries, potentially leading to unauthorized data access or modification. Organizations using affected versions of the Geolocation Field should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-13242
Severity
MEDIUM
CVSS
6.5
EPSS
0.17%

Original NVD Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. This issue affects Geolocation Field versions: from 0.0.0 to 3.15.0.