Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Iancawthorne

#40793of 53,632
6.5Total CVSS
Vulnerabilities · 1
PT-2019-8593
6.5
2017-06-24
Drupal · Drupal · CVE-2017-6922
**Name of the Vulnerable Software and Affected Versions** Drupal core versions prior to 8.3.4 Drupal core versions prior to 7.56 **Description** The issue allows an access bypass, where private files uploaded by an anonymous user are visible to all anonymous users, rather than just the user who uploaded them. This occurs on sites that allow anonymous users to upload files into a private file system. **Recommendations** For Drupal core versions prior to 8.3.4, update to version 8.3.4 or later. For Drupal core versions prior to 7.56, update to version 7.56 or later.