File Entity (fieldable files) - Moderately critical - Cross Site Scripting, Access bypass - SA-CONTRIB-2024-001

File Entity (fieldable files) - Moderately critical - Cross Site Scripting, Access bypass - SA-CONTRIB-2024-001

Project: File Entity (fieldable files)
Date: 2024-January-10
Security risk: Moderately critical 14∕25
Vulnerability: Cross Site Scripting, Access bypass

Description

File entity provides interfaces for managing files. It also extends the core file entity, allowing files to be fieldable, grouped into types, viewed (using display modes) and formatted using field formatters.

The module previously did not sufficiently validate files under the scenario of a file replacement leading to multiple exploit paths including persistent Cross Site Scripting.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission to edit files.

Solution

Install the latest version:

If you use the file_entity module for Drupal 7.x, upgrade to File Entity 7.x-2.38.

We value your opinion. Please add your feedback.