Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4688
HistoryJul 26, 2017 - 3:27 a.m.

Authorization Bypass

2017-07-2603:27:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

EPSS

0.002

Percentile

55.4%

Drupal is vulnerable to authorization bypass. Through the File module, attackers are able to view, delete, or substitute links to a file uploaded to a form that has yet to be processed. If this attack is done continuously, file uploads to the application may be blocked by deleting files before they can be saved.

CPENameOperatorVersion
drupal/corele8.0.3
drupal/drupalle8.0.3