Lucene search

K
osvGoogleOSV:GHSA-CMMH-8MWP-GQ5P
HistoryMay 24, 2022 - 4:56 p.m.

Drupal Cross Site Scripting (XSS) vulnerability

2022-05-2416:56:28
Google
osv.dev
9
drupal
cross site scripting
file upload

AI Score

5.6

Confidence

High

EPSS

0.682

Percentile

98.0%

In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.

References