A vulnerability existed in the File module that allowed a malicious user to view, delete or substitute a link to a file that the victim had uploaded to a form while the form had not yet been submitted and processed. If an attacker carried out this attack continuously, all file uploads to a site could be blocked by deleting all temporary files before they could be saved.

This vulnerability is mitigated by the fact that the attacker must have permission to create content or comment and upload files as part of that process.

Part of security release SA-CORE-2016-001

This vulnerability affects the following application versions:

  • Drupal 7.0
  • Drupal 7.1
  • Drupal 7.2
  • Drupal 7.3
  • Drupal 7.4
  • Drupal 7.5
  • Drupal 7.6
  • Drupal 7.7
  • Drupal 7.8
  • Drupal 7.9
  • Drupal 7.10
  • Drupal 7.11
  • Drupal 7.12
  • Drupal 7.13
  • Drupal 7.14
  • Drupal 7.15
  • Drupal 7.16
  • Drupal 7.17
  • Drupal 7.18
  • Drupal 7.19
  • Drupal 7.20
  • Drupal 7.21
  • Drupal 7.22
  • Drupal 7.23
  • Drupal 7.24
  • Drupal 7.25
  • Drupal 7.26
  • Drupal 7.27
  • Drupal 7.28
  • Drupal 7.29
  • Drupal 7.30
  • Drupal 7.31
  • Drupal 7.32
  • Drupal 7.33
  • Drupal 7.34
  • Drupal 7.35
  • Drupal 7.36
  • Drupal 7.37
  • Drupal 7.38
  • Drupal 7.39
  • Drupal 7.40
  • Drupal 7.41
  • Drupal 7.42
  • Drupal 8.0.0
  • Drupal 8.0.1
  • Drupal 8.0.2
  • Drupal 8.0.3

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *