PT-2025-30312 · Drupal · Drupal File Download

Greg Knaddison

+3

·

Published

2025-07-21

·

Updated

2025-07-21

·

CVE-2025-7717

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Drupal File Download versions 0.0.0 through 1.8.9 Drupal File Download versions 2.0.0 through 2.0.0
Description The File Download module is susceptible to a missing authorization issue, allowing for forceful browsing.
Recommendations Update to a version prior to 1.9.0. Update to a version prior to 2.0.1.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-7717
DRUPAL-CONTRIB-2025-089

Affected Products

Drupal File Download