VYPR
Medium severity5.4NVD Advisory· Published Mar 26, 2019· Updated Jun 17, 2026

CVE-2019-6341

CVE-2019-6341

Description

In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
drupal/corePackagist
>= 7.0.0, < 7.65.07.65.0
drupal/corePackagist
>= 8.0.0, < 8.5.148.5.14
drupal/corePackagist
>= 8.6.0, < 8.6.138.6.13
drupal/drupalPackagist
>= 7.0.0, < 7.65.07.65.0
drupal/drupalPackagist
>= 8.0.0, < 8.5.148.5.14
drupal/drupalPackagist
>= 8.6.0, < 8.6.138.6.13

Affected products

7

Patches

Vulnerability mechanics

References

19

News mentions

0

No linked articles in our index yet.