Drupal Allow All File Extensions Vulnerability in File Fields
Vulnerability
A vulnerability exists in Drupal that allows all file extensions to be uploaded through file fields. This issue specifically impacts file fields configured to accept any file type, denoted by '*.*'.
Impact
Exploitation of this vulnerability could lead to the upload of potentially harmful files, such as scripts or executables, which could be executed on the server or client side, depending on the file type and application context.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
6.4remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
