The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2016-04-12 08:59
Updated : 2016-04-22 07:11
NVD link : CVE-2016-3162
Mitre link : CVE-2016-3162
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
debian
- debian_linux
drupal
- drupal