Critical severity9.8NVD Advisory· Published Dec 16, 2019· Updated Jun 17, 2026
CVE-2019-19826
CVE-2019-19826
Description
The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_Tar object, for file deletion. Code execution might also be possible.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:drupal:views_dynamic_field:*:*:*:*:*:drupal:*:*+ 4 more
- cpe:2.3:a:drupal:views_dynamic_field:*:*:*:*:*:drupal:*:*range: <=6.x-1.4
- cpe:2.3:a:drupal:views_dynamic_field:7.x-1.0:alpha1:*:*:*:drupal:*:*
- cpe:2.3:a:drupal:views_dynamic_field:7.x-1.0:alpha2:*:*:*:drupal:*:*
- cpe:2.3:a:drupal:views_dynamic_field:7.x-1.0:alpha3:*:*:*:drupal:*:*
- cpe:2.3:a:drupal:views_dynamic_field:7.x-1.0:alpha4:*:*:*:drupal:*:*
- Drupal/Views Dynamic Fieldsdescription
- Range: <=7.x-1.0-alpha4
Patches
Vulnerability mechanics
References
1- www.drupal.org/project/views_dynamic_fields/issues/3056600nvdVendor Advisory
News mentions
0No linked articles in our index yet.