Junglewise Threat Intelligence

CVE-2026-15081: Drupal Location Selector SQL injection in Views filter

CVE-2026-15081 · Severity: info · CVSS 8.8 · Published 2026-07-10

Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The Location Selector module for Drupal, which allows users to select geographic locations via the GeoNames API, contains a security flaw. An attacker could exploit this to run unauthorized database commands, potentially leading to the theft of sensitive data or full site compromise. This risk is present if a site uses the module's search filters and allows visitors to input their own location data.

Technical details

The Location Selector module fails to sufficiently sanitize user-supplied input within its Views filter component. Specifically, when a View is configured to use the affected filter and is exposed to user input, an attacker can inject malicious SQL commands. This is a classic SQL injection (CWE-89) vulnerability resulting from improper neutralization of special elements. The vulnerability is mitigated only if no Views exist that utilize the affected filter with user-exposed inputs. The issue is fixed in version 1.3.0.

Affected products

  • Drupal Location Selector 0.0.0 to 1.2.x (fixed in 1.3.0)

Timeline

  • 2026-07-07: patched: Version 1.3.0 released
  • 2026-07-08: advisory: Drupal security advisory SA-CONTRIB-2026-072 published
  • 2026-07-10: disclosed: CVE-2026-15081 published to NVD

References