Vulnerability Bulletins

Drupal Core - Critical - Multiple Vulnerabilities - SA-CORE-2016-001

   
Affected software Drupal
 
Advisory ID: SA-CORE-2016-001Project: Drupal core Version: 6.x, 7.x, 8.xDate: 2016-February-24Security risk: 15/25 ( Critical) AC:Basic/A:User/CI:Some/II:Some/E:Proof/TD:AllVulnerability: Multiple vulnerabilitiesDescriptionFile upload access bypass and denial of service (File module - Drupal 7 and 8 - Moderately Critical)A vulnerability exists in the File module that allows a malicious user to view, delete or substitute a link to a file that the victim has uploaded to a form while the form has

More info:

https://www.drupal.org/SA-CORE-2016-001