CVE-2017-6377

HIGH7.5EPSS 0.29%

Drupal editor module incorrectly checks access to inline private files

發布日:2022/5/13修改日:2024/4/23

描述

When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

參考連結(7)