Drupal Access bypass in private file fields on comments Vulnerability
22 Apr. 2011
Summary
Drupal 7 contains two new features: the ability to attach File upload fields to any entity type in the system and the ability to point individual File upload fields to the private file directory.
Credit:
The information has been provided by Florian Weber..
Drupal 7 contains two new features: the ability to attach File upload fields to any entity type in the system and the ability to point individual File upload fields to the private file directory.
If a Drupal site is using these features on comments, and the parent node is denied access (either by a node access module or by being unpublished), the file attached to the comment can still be downloaded by non-privileged users if they know or guess its direct URL.
This issue affects Drupal 7.x only.
Vendor Status:
Drupal issued an update for this vulnerability