Arbitrary Script Injection in Field Group Module for Drupal

Arbitrary Script Injection in Field Group Module for Drupal

CVE-2016-1565 · LOW Severity

AV:N/AC:M/AU:S/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in the Field Group module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with permission to configure field display settings to inject arbitrary web script or HTML via an element attribute.

Learn more about our Web App Pen Testing.