SB2016091915 - File upload access bypass in Drupal Drupal 



SB2016091915 - File upload access bypass in Drupal Drupal

Published: September 19, 2016

Security Bulletin ID SB2016091915
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) File upload access bypass (CVE-ID: N/A)

The vulnerability allows a remote unprivileged user to attach files to content and view attached files.
The weakness exists due to logic error in the core upload module validation that allows attackers to access applied files that was forbidden for him before.
Successful exploitation of the vulnerability allows a malicious user to obtain attached files.

Remediation

Install update from vendor's website.