QID 154135

Date Published: 2023-05-24

QID 154135: Drupal Core: Incorrect Authorization Vulnerability (CVE-2023-31250)

Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.

The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files that they should not have access to.

Affected Versions:
Drupal 7.0 to 7.95
Drupal 9.4 to 9.4.13
Drupal 9.5 to 9.5.7
Drupal 10.0 to 10.0.7

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.

Users may be able to gain unauthorized access to confidential files that are meant to be restricted.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to install latest Drupal version.
    For more information visit Drupal security advisory SA-CORE-2023-005.
    Vendor References

    CVEs related to QID 154135

    Software Advisories
    Advisory ID Software Component Link
    SA-CORE-2023-005 URL Logo www.drupal.org/sa-core-2023-005