CVE-2019-19826: Critical severity drupal views vulnerability
The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/viewshandlerfilterdynamicfields.inc, as demonstrated by PHP object injection, involving a fieldnames object and an ArchiveTar object, for file deletion. Code execution might also be possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19826?
CVE-2019-19826 has a moderate to high severity rating due to its potential for PHP object injection and code execution.
How do I fix CVE-2019-19826?
To fix CVE-2019-19826, update the Views Dynamic Fields module to a secure version beyond 7.x-1.0-alpha4.
What versions of Drupal are affected by CVE-2019-19826?
CVE-2019-19826 affects Drupal Views Dynamic Fields module versions up to and including 7.x-1.0-alpha4.
What kind of attacks can CVE-2019-19826 facilitate?
CVE-2019-19826 can facilitate attacks involving PHP object injection and arbitrary file deletion.
Is user authentication required to exploit CVE-2019-19826?
Exploitation of CVE-2019-19826 typically does not require user authentication, increasing its potential risk.