VYPR
Unrated severityNVD Advisory· Published Dec 1, 2014· Updated Jun 17, 2026

CVE-2014-9156

CVE-2014-9156

Description

The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not properly check permissions to view files, which allows remote authenticated users with permission to create or edit content to read private files by attaching an uploaded file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.