CVE-2016-1565

MEDIUM

Drupal 7.x-1.x - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the Field Group module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with permission to configure field display settings to inject arbitrary web script or HTML via an element attribute.

Scores

CVSS v3 6.1
EPSS 0.0019
EPSS Percentile 40.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-79
Status draft

Affected Products (7)

field_group_project/field_group
field_group_project/field_group
field_group_project/field_group
field_group_project/field_group
field_group_project/field_group
field_group_project/field_group
field_group_project/field_group

Timeline

Published Jan 08, 2016
Tracked Since Feb 18, 2026