CVE-2012-5538: XSS
Cross-site scripting (XSS) vulnerability in the FileField Sources module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.6 for Drupal, when the field has "Reference existing" source enabled, allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5538?
CVE-2012-5538 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2012-5538?
To fix CVE-2012-5538, upgrade the FileField Sources module to version 6.x-1.6 or 7.x-1.6 or later.
Who is affected by CVE-2012-5538?
CVE-2012-5538 affects users of the FileField Sources module for Drupal versions 6.x-1.0 to 6.x-1.5 and 7.x-1.2 to 7.x-1.5.
What versions of FileField Sources are vulnerable to CVE-2012-5538?
Versions 6.x-1.0 to 6.x-1.5 and 7.x-1.2 to 7.x-1.5 of the FileField Sources module are vulnerable to CVE-2012-5538.
Can CVE-2012-5538 be exploited by unauthenticated users?
No, CVE-2012-5538 requires remote authenticated users to exploit the vulnerability.