CVE Database
/

CVE-2014-5020

Back to search

CVE-2014-5020

Published: Jul 22, 2014

Modified: Sep 16, 2024

PUBLISHED

Description

The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-2983
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now