Exif - Critical - Access bypass - SA-CONTRIB-2018-017

Project: Exif
Version: 8.x-1.x-dev
Date: 2018-March-21
Security risk: *Critical* 16∕25
Vulnerability: Access bypass

Description

This module enables you to retrieve image metadata and use them in fields or
title.

The module doesn't sufficiently restrict access to module setting pages
thereby causing an access bypass vulnerability.

This vulnerability is mitigated by the fact that an attacker must have
permission to create entities of certain content entity types.

Читайте на сайте