Executive brief
The Location Selector module for Drupal, which allows users to select geographic locations via the GeoNames API, contains a security flaw. An attacker could exploit this to run unauthorized database commands, potentially leading to the theft of sensitive data or full site compromise. This risk is present if a site uses the module's search filters and allows visitors to input their own location data.
Technical details
The Location Selector module fails to sufficiently sanitize user-supplied input within its Views filter component. Specifically, when a View is configured to use the affected filter and is exposed to user input, an attacker can inject malicious SQL commands. This is a classic SQL injection (CWE-89) vulnerability resulting from improper neutralization of special elements. The vulnerability is mitigated only if no Views exist that utilize the affected filter with user-exposed inputs. The issue is fixed in version 1.3.0.
Affected products
- Drupal Location Selector 0.0.0 to 1.2.x (fixed in 1.3.0)
Timeline
- 2026-07-07: patched: Version 1.3.0 released
- 2026-07-08: advisory: Drupal security advisory SA-CONTRIB-2026-072 published
- 2026-07-10: disclosed: CVE-2026-15081 published to NVD