Drupal core has a reflected file download vulnerability that could allow an attacker to trick a user into downloading and running a file with arbitrary JSON-encoded content.
This vulnerability is mitigated by the fact that the victim must be a site administrator and that the full version of the attack only works with certain web browsers.
https://www.drupal.org/SA-CORE-2016-001
This vulnerability affects the following application versions:
- Drupal 7.0
- Drupal 7.1
- Drupal 7.2
- Drupal 7.3
- Drupal 7.4
- Drupal 7.5
- Drupal 7.6
- Drupal 7.7
- Drupal 7.8
- Drupal 7.9
- Drupal 7.10
- Drupal 7.11
- Drupal 7.12
- Drupal 7.13
- Drupal 7.14
- Drupal 7.15
- Drupal 7.16
- Drupal 7.17
- Drupal 7.18
- Drupal 7.19
- Drupal 7.20
- Drupal 7.21
- Drupal 7.22
- Drupal 7.23
- Drupal 7.24