CVE-2011-4972: Infoleak
Published Nov 13, 2019
·Updated
hookfiledownload in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.
Affected Software
1 affected component
CKEditor Ckeditor Drupal=7.x-1.4
Remediation
Patch Available
Event History
Nov 13, 2019
CVE Published
via MITRE·08:51 PM
Data Sourced
via MITRE·08:51 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2011-4972?
The severity of CVE-2011-4972 is high.
2
What is the affected software for CVE-2011-4972?
The affected software for CVE-2011-4972 is CKEditor module 7.x-1.4 for Drupal.
3
How does CVE-2011-4972 impact Drupal websites?
CVE-2011-4972 allows remote attackers to read private files on Drupal websites.
4
Are there any fixes available for CVE-2011-4972?
Yes, fixes for CVE-2011-4972 are available on the Drupal website.
5
Where can I find more information about CVE-2011-4972?
You can find more information about CVE-2011-4972 on the Drupal website and Openwall.