#VU100759 Input validation error in Drupal

 

#VU100759 Input validation error in Drupal

Published: November 21, 2024


Vulnerability identifier: #VU100759
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Drupal
Software vendor:
Drupal

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the PHP Object Injection issue in the "unserialize()" function. A remote user can pass specially crafted input to the application and delete arbitrary files on the system.

According to the vendor the vulnerability is not directly exploitable.


Remediation

Install updates from vendor's website.

External links