Project: 
Project machine name: 
xsendfile
Date: 
2023-November-29
Vulnerability: 
Access bypass
Affected versions: 
<1.2.0
Description: 

The Xsendfile module enables fast transfer for private files in Drupal.

In order to control private file downloads, the module overrides ImageStyleDownloadController, for which a vulnerability was disclosed in SA-CORE-2023-005. The Xsendfile module was still based on an insecure version of ImageStyleDownloadController.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: