ZeroHour

CVE-2016-1565

CVSS 3.0
6.1 medium
EPSS
<1%p48
Published
()
Modified
Description

Cross-site scripting (XSS) vulnerability in the Field Group module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with permission to configure field display settings to inject arbitrary web script or HTML via an element attribute.

Vendors
field group project
Products
field group
Ecosystems
Drupal
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.