ZeroHour

CVE-2016-3162

CVSS 3.0
8.1 high
EPSS
2%p74
Published
()
Modified
Description

The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files.

Vendors
drupaldebian
Products
drupal, debian linux
Ecosystems
Drupal
Weakness
CWE-284
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.