PT-2009-6010 · Drupal · Filefield

CVE-2009-3781

·

Publicado

2009-10-26

·

Atualizado

2024-02-02

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FileField versions 6.x-3.1
Description The issue concerns the filefield file download function, which does not properly check node-access permissions for Drupal core private files. This allows remote attackers to access unauthorized files via unspecified vectors.
Recommendations For FileField version 6.x-3.1, consider disabling the filefield file download function until a patch is available to prevent unauthorized file access.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-3781

Produtos afetados

Filefield