CVE-2011-4972
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which a
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.
HIGH · CVSS 7.5
EPSS 0.00909
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0