PT-2026-48592 · Drupal+2 · Examples For Developers+2
CVSS v3.1
3.3
Low
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Examples for Developers versions 0.0.0 through 4.0.6
Description
A missing authorization issue allows forceful browsing. Specifically, the "Read from a file" feature within the
file example submodule can be used to expose any file that PHP can access, leading to an access bypass.Recommendations
Remove the
file example submodule from Examples for Developers versions 0.0.0 through 4.0.6.
Developers who based a new module on this example should review their code for an access bypass.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Examples For Developers
Drupal/Examples
Examples