VendorsNathan Haugfilefield_sources7.x-1.5
Vulnerabilities

Nathan Haug FileField Sources module for Drupal 7.x-1.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2013-4502
The FileField Sources module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.9 for Drupal does not properly check file permissions, which allows remote authenticated users to read arbitrary files by attaching a file.
Published 2014-05-13 · Modified
4.0EPSS 0.011
CVE-2012-5538
Cross-site scripting (XSS) vulnerability in the FileField Sources module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.6 for Drupal, when the field has "Reference existing" source enabled, allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.
Published 2012-12-03 · Modified
2.1EPSS 0.009