Updated January 9th, 2020
This module enables you to import taxonomy terms from different sources, including a text area, a file upload or a file present in the web server.
The module doesn't sufficiently validate user input when providing a local
filename to import.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "import taxonomy by csv".
Original advisory:
The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported
Install the latest version:
- If you use the Taxonomy CSV module for Drupal 7.x, upgrade to taxonomy_csv 7.x-5.11
- Ariel Barreiro, the module maintainer
- David Snopek of the Drupal Security Team