CVE-2011-4972
13.11.2019, 21:15
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.Enginsight
Vendor | Product | Version |
---|---|---|
ckeditor | ckeditor | 7.x-1.4:x |
𝑥
= Vulnerable software versions
Common Weakness Enumeration