drupal/search_api_autocomplete is vulnerable to Cross-Site Scripting (XSS)
56
Medium Risk
This module adds autocomplete suggestions for Search API search forms. It ships with a test script that is accessible to anonymous users and does not sufficiently validate user input, leading to cross-site scripting. Exploitation is mitigated when the web server is not configured to display PHP warning messages to users.
You are affected if you are using a version that falls within the vulnerable range and your PHP or web server configuration displays warning messages to users (for example, with display_errors enabled).
drupal/search_api_autocomplete is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 1.11.0.
Upgrade the drupal/search_api_autocomplete module to the patch version. If you cannot update immediately, set display_errors: off in php.ini or equivalent settings.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant