The Webform Multifile File Upload module contains a Remote Code Execution (RCE) vulnerability exists where form inputs will be unserialized and a specially crafted form input may trigger arbitrary code execution depending on the libraries available on a site.

With the help of the D6LTS vendors, a new version was released:

https://www.drupal.org/project/webform_multifile/releases/6.x-1.4

The patch to fix is also attached.

CommentFileSizeAuthor
SA-CONTRIB-2016-038.patch10.74 KBdsnopek
Support from Acquia helps fund testing for Drupal Acquia logo

Comments

dsnopek created an issue. See original summary.

dsnopek’s picture

Status: Active » Fixed

Committed!

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.