vulnerability
FreeBSD: VID-94d63fd7-508b-11e9-9ba0-4c72b94353b5 (CVE-2019-6341): drupal -- Drupal core - Moderately critical - Cross Site Scripting
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 3 | (AV:N/AC:M/Au:S/C:N/I:P/A:N) | Mar 27, 2019 | Apr 1, 2019 | Jun 15, 2026 |
Severity
3
CVSS
(AV:N/AC:M/Au:S/C:N/I:P/A:N)
Published
Mar 27, 2019
Added
Apr 1, 2019
Modified
Jun 15, 2026
Description
In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.
Solutions
freebsd-upgrade-package-drupal7freebsd-upgrade-package-drupal8
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.