CVE-2016-3162: High severity drupal vulnerability
File upload access bypass and denial of service
Other sources
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3162?
CVE-2016-3162 has a severity rating of highly critical due to its potential for file upload access bypass and denial of service.
How do I fix CVE-2016-3162?
To fix CVE-2016-3162, update your Drupal installation to version 7.43 or 8.0.4 or later.
Which versions are affected by CVE-2016-3162?
CVE-2016-3162 affects Drupal versions 7.x before 7.43 and 8.x before 8.0.4.
What is the impact of CVE-2016-3162?
The impact of CVE-2016-3162 includes unauthorized access to files and potential denial of service, which may compromise sensitive data.
Who can exploit CVE-2016-3162?
CVE-2016-3162 can be exploited by remote authenticated users who have permission to create content.