The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not properly check permissions to view files, which allows remote authenticated users with permission to create or edit content to read private files by attaching an uploaded file.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.drupal.org/node/2304517 | vendor advisory |
https://www.drupal.org/node/2304561 | vendor advisory |
http://cgit.drupalcode.org/filefield/commit/?id=3a97fe1 | vendor advisory |