PT-2026-63534 · Drupal+2 · Media Folders+1
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal Media Folders versions 0.0.0 through 1.0.8
Description
Stored cross-site scripting (XSS) occurs because the module does not sufficiently sanitize the names and descriptions of media items and folders when they are displayed in the media browser. This allows an attacker with permissions to create or edit media items or folders to inject malicious scripts. Cross-site scripting is a technique where malicious scripts are injected into trusted websites.
Recommendations
Update Drupal Media Folders to a version later than 1.0.8.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Media Folders
Drupal/Media Folders