Downloads

Download webform_multifile-6.x-1.4.tar.gztar.gz 99 KB
MD5: d4d16a14bca990696e51f89d7afb8290
SHA-1: 5cdd943ef6b5c64da01808c2f85ee004c3a58d52
SHA-256: 8078096582f0a6f1ac25184770089939955574ef4a5040ab11ba675da324a4ee
Download webform_multifile-6.x-1.4.zipzip 105.44 KB
MD5: 770342aad4f2187648b146b3f5870bd0
SHA-1: 7056431817fdb7c6355395d14983a32f4011dc64
SHA-256: 430f2c07df1ee389328fc7f75bdb18474a1685c2d67a3b6a06945c9244f5f149

Release notes

The Webform Multifile File Upload module contains a Remote Code Execution (RCE) vulnerability exists where form inputs will be unserialized and a specially crafted form input may trigger arbitrary code execution depending on the libraries available on a site.

This vulnerability is mitigated by the fact that an attacker must have the ability to submit a Webform with a Multiple File Input field. Further, a site must have an object defined with methods that are invoked at wake/destroy that include code that can be leveraged for malicious purposes (Drupal 7 Core contains one such class which can be used to delete arbitrary files).

Created by: attiks
Created on: 13 Jul 2016 at 07:50 UTC
Last updated: 26 Jan 2022 at 21:39 UTC
Security update
Insecure

Other releases