Reflected File Download Affecting drupal/drupal package, versions >=6.0.0, <6.38>=7.0.0, <7.43


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.26% (67th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-DRUPALDRUPAL-70072
  • published15 Feb 2016
  • disclosed15 Feb 2016
  • creditJuho Nurminen, David Rothstein, Damien Tournoud, Peter Wolanin, Nate Haug

Introduced: 15 Feb 2016

CVE-2016-3168  (opens in a new tab)
CWE-494  (opens in a new tab)
First added by Snyk

How to fix?

Upgrade drupal/drupal to version 6.38, 7.43 or higher.

Overview

Affected versions of drupal/drupal are vulnerable to Reflected File Download.

The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "Reflected File Download."

CVSS Scores

version 3.1