---
cve: "CVE-2019-6341"
severity: "LOW"
cvss: 3.1
epss: "12.2%"
vendor: "Drupal"
kev: false
exploited: false
published: "2019-03-26 18:29:01"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-10T11:43:34+02:00"
---

# CVE-2019-6341

> 3.1 LOW

## Beschreibung

In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.

## Patch verfügbar (OSV)

- c2cae51e5c32296f6129edb0bc08d5d2b38b92c9 (Commit)
- 471af00dd8660843b8fe3108b8b74d92013b4804 (Commit)

## Referenzen

- <https://www.drupal.org/sa-core-2019-004>
- <https://lists.debian.org/debian-lts-announce/2019/04/msg00003.html>
- <https://www.synology.com/security/advisory/Synology_SA_19_13>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QNTLCBAN6T7WYR5C4TNEYQD65IIR3V4P/>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4SVTVIJ33XCFQ6X6XTVMQM3NPLP2WFS/>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P4KTET2PTSIS3ZZ4SGBRQEN6CCLV5SYX/>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IWHF4LALNBZCXMITWWVWKY3PNVYTM3N7/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2019-6341) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
