In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.
2019-03-26T18:29:01.027
2024-11-21T04:46:26.710
Modified
CVSSv3.0: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | drupal | drupal | < 7.65 | Yes |
Application | drupal | drupal | < 8.5.14 | Yes |
Application | drupal | drupal | < 8.6.13 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | fedoraproject | fedora | 28 | Yes |
Operating System | fedoraproject | fedora | 29 | Yes |