Project:
Date:
2018-February-07
Vulnerability:
Access Bypass
Description:
This module enables you to upload files to fields via several sources.
The module doesn't sufficiently handle access control under the scenario of the autocomplete path of reference sources.
Solution:
Install the latest version:
- If you use the filefield_sources module provided reference source for Drupal 7.x, upgrade to 7.x-1.11.
Reported By:
- Tatar Balazs Janos Provisional Security Team member
Fixed By:
- Tatar Balazs Janos Provisional Security Team member
- Nate Lampton the module maintainer
Coordinated By:
- Michael Hess of the Drupal Security Team