PT-2009-6010 · Drupal · Filefield
CVE-2009-3781
·
Publicado
2009-10-26
·
Atualizado
2024-02-02
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FileField versions 6.x-3.1
Description
The issue concerns the
filefield file download function, which does not properly check node-access permissions for Drupal core private files. This allows remote attackers to access unauthorized files via unspecified vectors.Recommendations
For FileField version 6.x-3.1, consider disabling the
filefield file download function until a patch is available to prevent unauthorized file access.Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Filefield