Описание
The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary files as attachments.
Ссылки
- Patch
- PatchVendor Advisory
- Patch
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
Одно из
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha7:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha8:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:beta1:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:beta2:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.x:dev:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00364
Низкий
4 Medium
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
около 3 лет назад
The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary files as attachments.
EPSS
Процентиль: 58%
0.00364
Низкий
4 Medium
CVSS2
Дефекты
CWE-264