CVE-2012-5538

Drupal FileField Sources <7.x-1.6 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the FileField Sources module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.6 for Drupal, when the field has "Reference existing" source enabled, allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.

Scores

EPSS 0.0020
EPSS Percentile 42.0%

Details

CWE
CWE-79
Status published
Products (13)
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
nathan_haug/filefield_sources
... and 3 more
Published Dec 03, 2012
Tracked Since Feb 18, 2026