CVE-2019-6341: Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2019-004
In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.
Other sources
In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.
Moderately critical - Cross Site Scripting - SA-CORE-2019-004
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6341?
CVE-2019-6341 has been rated as a moderate severity vulnerability.
How do I fix CVE-2019-6341?
To fix CVE-2019-6341, upgrade Drupal to version 7.65, 8.5.14, or 8.6.13 or later.
What systems are affected by CVE-2019-6341?
CVE-2019-6341 affects Drupal 7 versions prior to 7.65, Drupal 8.5 versions prior to 8.5.14, and Drupal 8.6 versions prior to 8.6.13.
Can CVE-2019-6341 lead to data compromise?
Yes, CVE-2019-6341 can allow an attacker to upload malicious files leading to potential data compromise.
What type of vulnerability is CVE-2019-6341?
CVE-2019-6341 is a cross-site scripting (XSS) vulnerability that can be exploited under certain conditions.