First published: Wed Apr 04 2018(Updated: )
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
Credit: larry0@me.com
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Avatar Uploader | =7.x-1.0-beta8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9205 is considered a moderate severity vulnerability due to its potential for unauthorized file access.
To fix CVE-2018-9205, you should upgrade the avatar_uploader module to a version that addresses this vulnerability.
Any Drupal sites using avatar_uploader version 7.x-1.0-beta8 are affected by CVE-2018-9205.
The consequences of CVE-2018-9205 include the risk of malicious users uploading unauthorized files due to insufficient validation.
Yes, CVE-2018-9205 is a publicly known vulnerability that has been documented in various security advisories.