Date: 
2019-November-13
Vulnerability: 
Information disclosure
Description: 

Updated January 9th, 2020

This module enables you to import taxonomy terms from different sources, including a text area, a file upload or a file present in the web server.

The module doesn't sufficiently validate user input when providing a local
filename to import.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "import taxonomy by csv".

Original advisory:

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

Solution: 

Install the latest version:

Reported By: 
Fixed By: 
Coordinated By: