Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary files as attachments.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal Mime Mail模块安全漏洞
Vulnerability Description
Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。 Drupal中的Mime Mail模块6.x-1.1之前的6.x-1.x版本中存在漏洞,该漏洞源于没有正确对Drupal的发布文件目录以外的文件进行访问限制。远程认证攻击者利用该漏洞以附件形式发送任意文件。
CVSS Information
N/A
Vulnerability Type
N/A