QID 154137

Date Published: 2023-05-24

QID 154137: Drupal Core: Information Disclosure Vulnerability (CVE-2022-25275)

Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.

In some situations, the Image module does not correctly check access to image files not stored in the standard public files directory when generating derivative images using the image styles system.

Affected Versions:
Drupal 7.0 to 7.90
Drupal 8.0.0 to 9.3.18
Drupal 9.4.0 to 9.4.2

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.

Successful exploitation would lead to Information Disclosure vulnerability, which can help the attacker carry out further attacks and obtain sensitive information.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to install latest Drupal version.
    For more information visit Drupal security advisory SA-CORE-2022-012.
    Vendor References

    CVEs related to QID 154137

    Software Advisories
    Advisory ID Software Component Link
    SA-CORE-2022-012 URL Logo www.drupal.org/sa-core-2022-012