| |
Vulnerability CVE-2014-5020
Published: 2014-07-22
Description: |
The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field. |
Type:
CWE-264 (Permissions, Privileges, and Access Controls)
CVSS2 => (AV:N/AC:M/Au:S/C:P/I:P/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
4.9/10 |
4.9/10 |
6.8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Medium |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
Partial |
None |
References: |
https://www.drupal.org/SA-CORE-2014-003
http://www.debian.org/security/2014/dsa-2983
|
|
|
Copyright 2024, cxsecurity.com
|
|
|