CVE-2012-5538
Drupal FileField Sources <7.x-1.6 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the FileField Sources module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.6 for Drupal, when the field has "Reference existing" source enabled, allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.
Scores
EPSS
0.0020
EPSS Percentile
42.0%
Details
CWE
CWE-79
Status
published
Products (13)
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
... and 3 more
Published
Dec 03, 2012
Tracked Since
Feb 18, 2026