VYPR

FileField

by Drupal

CVEs (2)

  • CVE-2014-9156Dec 1, 2014
    risk 0.00cvss epss 0.02

    The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not properly check permissions to view files, which allows remote authenticated users with permission to create or edit content to read private files by attaching an uploaded file.

  • CVE-2009-3781Oct 26, 2009
    risk 0.00cvss epss 0.02

    The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors.