CyberRota Analysis
AI-GeneratedThe Drupal Location Selector component, versions 0.0.0 to 1.3.0, is vulnerable to SQL injection due to improper handling of special elements in SQL commands. This flaw could allow attackers to execute arbitrary SQL queries, potentially compromising the integrity and confidentiality of the database. Organizations using affected versions of the Location Selector should prioritize patching this vulnerability to mitigate the risk of exploitation.
CVE
CVE-2026-15081
Severity
HIGH
CVSS
7.4
EPSS
0.26%
Original NVD Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0.