CVE-2008-3219

Drupal <5.8, <6.3 - XSS

Title source: llm

Description

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.

Scores

EPSS 0.0092
EPSS Percentile 75.7%

Classification

CWE
CWE-79
Status draft

Affected Products (3)

drupal/drupal < 5.8
fedoraproject/fedora
fedoraproject/fedora

Timeline

Published Jul 18, 2008
Tracked Since Feb 18, 2026