Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072
View online: https://www.drupal.org/sa-contrib-2026-072 Project: Location Selector [1] Date: 2026-July-08 Security risk: *Critical* 19 ∕ 25 AC:Basic/A:None/CI:All/II:All/E:Theoretical/TD:Default [2] Vulnerability: SQL Injection Affected versions: <1.3.0 CVE IDs: CVE-2026-15081 Description: The Location Selector module provides a Views filter for selecting location values. One of the provided Views filters does not sufficiently sanitize values that may come from user input, resulting in a SQL injection vulnerability. This vulnerability is mitigated by the fact that a View must exist that uses the affected filter and is configured to accept user input. Solution: Install the latest version: * If you use the Location Selector module for Drupal, upgrade to Location Selector 8.x-1.3 [3] Reported By: * Drew Webber (mcdruid) [4] of the Drupal Security Team Fixed By: * handkerchief [5] Coordinated By: * Greg Knaddison (greggles) [6] of the Drupal Security Team * Drew Webber (mcdruid) [7] of the Drupal Security Team * Juraj Nemec (poker10) [8] of the Drupal Security Team Security issue: https://git.drupalcode.org/security/185258-location_selector-security/-/work_ite… [9] ------------------------------------------------------------------------------ Contribution record [10] [1] https://www.drupal.org/project/location_selector [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/location_selector/releases/8.x-1.3 [4] https://www.drupal.org/u/mcdruid [5] https://www.drupal.org/u/handkerchief [6] https://www.drupal.org/u/greggles [7] https://www.drupal.org/u/mcdruid [8] https://www.drupal.org/u/poker10 [9] https://git.drupalcode.org/security/185258-location_selector-security/-/work... [10] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org