GHSA-qqxc-cppg-4xp8
Dashboard / Vulnerabilities / GHSA-qqxc-cppg-4xp8
Summary: Drupal Reflected file download vulnerability
Details: The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."
References: https://nvd.nist.gov/vuln/detail/CVE-2016-3168, https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2016-3168.yaml, https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2016-3168.yaml, https://github.com/drupal/core, https://www.drupal.org/SA-CORE-2016-001, http://www.debian.org/security/2016/dsa-3498, http://www.openwall.com/lists/oss-security/2016/02/24/19, http://www.openwall.com/lists/oss-security/2016/03/15/10
Affected packages
Package
Name: drupal/core
Purl: pkg:composer/drupal/core
Affected ranges
Type: ECOSYSTEM
Events:
