PT-2026-22087 · Drupal+2 · Islandora+1
Damien Mckenna
+5
·
Published
2026-02-25
·
Updated
2026-03-30
·
CVE-2026-3215
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal Islandora versions prior to 2.17.5
Description
A flaw exists in Drupal Islandora that allows for Cross-Site Scripting (XSS). The issue stems from insufficient sanitization of URI paths used in a custom route for attaching media to nodes. Exploitation requires an attacker to have the 'create media' permission and the ability to edit the node to which the media is attached. Islandora is an open-source digital asset management (DAM) framework that integrates with various open-source services in a distributed environment. The vulnerable component doesn't properly sanitize input during web page generation.
Recommendations
Update to Islandora version 2.17.5 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Islandora
Drupal/Islandora