DRUPAL-CONTRIB-2022-023

    Dashboard / Vulnerabilities / DRUPAL-CONTRIB-2022-023

    DRUPAL-CONTRIB-2022-023

    Published: 9 Feb 2022Last Modified: 10 Sept 2026

    Summary:

    Details: This module enables you to manage and delete files. The module doesn't sufficiently protect unmanaged files from view under the scenario unauthenticated user knows path to visit the view and can attempt to delete files which results in duplicate files being created. To mitigate this issue without deploying code, review all views that are based on Fancy File Delete and ensure they have an access control set to use the permission "administer unmanaged files entities".

    Affected packages

    Package

    Name: drupal/fancy_file_delete

    Purl: pkg:composer/drupal/fancy_file_delete?repository_url=https:%2F%2Fpackages.drupal.org%2F8

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.0.7

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    DRUPAL-CONTRIB-2022-023 | CVE-DB