Description
In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.
Remediation
References
Related Vulnerabilities
Dot CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2022-37033)
MySQL Other Vulnerability (CVE-2003-0780)
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.24)
WordPress 4.2.x Multiple Vulnerabilities (4.2 - 4.2.33)
phpBB Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2026-29199)