This module provides a better UI for managing and selecting Media entities in a folder structure.
The module doesn't sufficiently sanitize the names and descriptions of media items and folders when they are displayed in the media browser, resulting in a stored cross-site scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit media items or folders.
Install the latest version:
- If you use the Media Folders module, upgrade to Media Folder 1.0.8
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team