Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal File模块安全漏洞
Vulnerability Description
Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。File是其中的一个文件处理模块。 Drupal 7.43之前7.x版本和8.0.4之前8.x版本的File模块中存在安全漏洞。远程攻击者可借助创建内容或评论权限和上传文件权限利用该漏洞绕过访问限制,读取、删除或替换特定文件(上传到未处理表单)的链接。
CVSS Information
N/A
Vulnerability Type
N/A