Drupal File Entity Sensitive Information Insertion Vulnerability Allowing Forceful Browsing

Vulnerability

A vulnerability allowing the insertion of sensitive information into sent data has been identified in the Drupal File Entity module (fieldable files) versions 7.X-* prior to 7.X-2.39. This vulnerability enables forceful browsing by manipulating the data sent during file entity interactions.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information by manipulating file entity data, potentially allowing for forceful browsing scenarios.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.