GHSA-cmmh-8mwp-gq5p
Dashboard / Vulnerabilities / GHSA-cmmh-8mwp-gq5p
GHSA-cmmh-8mwp-gq5p
Summary: Drupal Cross Site Scripting (XSS) vulnerability
Details: In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File `module/subsystem` allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-6341, https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2019-6341.yaml, https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2019-6341.yaml, https://github.com/drupal/core, https://lists.debian.org/debian-lts-announce/2019/04/msg00003.html, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IWHF4LALNBZCXMITWWVWKY3PNVYTM3N7, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P4KTET2PTSIS3ZZ4SGBRQEN6CCLV5SYX, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QNTLCBAN6T7WYR5C4TNEYQD65IIR3V4P, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4SVTVIJ33XCFQ6X6XTVMQM3NPLP2WFS, https://lists.fedoraproject.org/archives/list/[email protected]/message/IWHF4LALNBZCXMITWWVWKY3PNVYTM3N7, https://lists.fedoraproject.org/archives/list/[email protected]/message/P4KTET2PTSIS3ZZ4SGBRQEN6CCLV5SYX, https://lists.fedoraproject.org/archives/list/[email protected]/message/QNTLCBAN6T7WYR5C4TNEYQD65IIR3V4P, https://lists.fedoraproject.org/archives/list/[email protected]/message/Y4SVTVIJ33XCFQ6X6XTVMQM3NPLP2WFS, https://www.drupal.org/sa-core-2019-004, https://www.synology.com/security/advisory/Synology_SA_19_13
Affected packages
Package
Name: drupal/core
Purl: pkg:composer/drupal/core
Affected ranges
Type: ECOSYSTEM
Events:
