Drupal FileField Module Information Disclosure

03 November 2009
Bookmark and Share
FileField is a module for the Drupal content manager. The application is exposed to an information disclosure issue because it fails to restrict access to certain resources. Specifically, the module fails to restrict access to files based on node access permissions when using Drupal core's private filesystem. FileField version 6.x-3.1 is affected by this issue.

Ref: http://drupal.org/node/611128

09.44.97 - CVE: Not Available
Platform: Web Application