CVE-2015-3390: Facebook Album Fetcher Project Facebook Album Fetcher
Low severity, CVSS 3.5. EPSS: 0.9% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in the Facebook Album Fetcher module for Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via unspecified vectors.
Affected products
- Facebook Album Fetcher Project Facebook Album Fetcher: version 7.x-1.x-dev only
Published 2015-04-21. Last modified 2026-06-17.