{"id":"CVE-2019-6341","aliases":["DRUPAL-CORE-2019-004","GHSA-cmmh-8mwp-gq5p"],"url":"https://o3.security/vulnerability/CVE-2019-6341","summary":"Drupal Cross Site Scripting (XSS) vulnerability","details":"In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.","published":"2019-03-26T18:29:01.027Z","modified":"2026-07-08T05:55:06.997437211Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.08604,"percentile":0.94741,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"drupal/core","fixedVersion":"7.65.0"},{"ecosystem":"Packagist","name":"drupal/core","fixedVersion":"8.5.14"},{"ecosystem":"Packagist","name":"drupal/core","fixedVersion":"8.6.13"},{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"7.65.0"},{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"8.5.14"},{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"8.6.13"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IWHF4LALNBZCXMITWWVWKY3PNVYTM3N7/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P4KTET2PTSIS3ZZ4SGBRQEN6CCLV5SYX/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QNTLCBAN6T7WYR5C4TNEYQD65IIR3V4P/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4SVTVIJ33XCFQ6X6XTVMQM3NPLP2WFS/"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/04/msg00003.html"},{"type":"ADVISORY","url":"https://www.synology.com/security/advisory/Synology_SA_19_13"},{"type":"FIX","url":"https://www.drupal.org/sa-core-2019-004"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:55:06.997437211Z"}}