VDB
Sign up
—

DRUPAL-CORE-2019-004

Quick fix

DRUPAL-CORE-2019-004 — drupal/core: upgrade to the fixed version with the command below.

composer require drupal/core:^8.5.14

Details

Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/drupal/core
Introduced in: 8.0.0Fixed in: 8.5.14
Fixcomposer require drupal/core:^8.5.14

References