CVE-2016-1565
MEDIUMDrupal 7.x-1.x - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Field Group module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with permission to configure field display settings to inject arbitrary web script or HTML via an element attribute.
Scores
CVSS v3
6.1
EPSS
0.0019
EPSS Percentile
40.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
draft
Affected Products (7)
field_group_project/field_group
field_group_project/field_group
field_group_project/field_group
field_group_project/field_group
field_group_project/field_group
field_group_project/field_group
field_group_project/field_group
Timeline
Published
Jan 08, 2016
Tracked Since
Feb 18, 2026