Medium
CVSS 6.0
Overview
The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors.
The core upload module in Drupal 5.x before 5.11 allows remote authenticated use...
The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: