SB2016091915 - File upload access bypass in Drupal Drupal
Published: September 19, 2016
Security Bulletin ID
SB2016091915
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) File upload access bypass (CVE-ID: N/A)
The vulnerability allows a remote unprivileged user to attach files to content and view attached files.The weakness exists due to logic error in the core upload module validation that allows attackers to access applied files that was forbidden for him before.
Successful exploitation of the vulnerability allows a malicious user to obtain attached files.
Remediation
Install update from vendor's website.