PT-2009-6010 · Drupal · Filefield

Published

2009-10-26

·

Updated

2024-02-02

·

CVE-2009-3781

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FileField versions 6.x-3.1
Description The issue concerns the filefield file download function, which does not properly check node-access permissions for Drupal core private files. This allows remote attackers to access unauthorized files via unspecified vectors.
Recommendations For FileField version 6.x-3.1, consider disabling the filefield file download function until a patch is available to prevent unauthorized file access.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2009-3781

Affected Products

Filefield