Drupal Core – Cross Site Scripting

Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.

Drupel security ID – SA-CORE-2019-004

Solution: 

Versions of Drupal 8 prior to 8.5.x are end-of-life and do not receive security coverage.Reported By: 

Duncan Newell

Duncan is a technology professional with over 20 years experience of working in various IT roles. He has a interest in cyber security, and has a wide range of other skills in radio, electronics and telecommunications.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

%d bloggers like this: