Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wpp8-x44c-v39q

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors.

The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors.

EPSS

Процентиль: 76%
0.00989
Низкий

Дефекты

CWE-862

Связанные уязвимости

nvd
больше 16 лет назад

The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors.

EPSS

Процентиль: 76%
0.00989
Низкий

Дефекты

CWE-862