Date: 
2024-January-10
Vulnerability: 
Cross Site Scripting, Access bypass
CVE IDs: 
CVE-2024-13237
Description: 

File entity provides interfaces for managing files. It also extends the core file entity, allowing files to be fieldable, grouped into types, viewed (using display modes) and formatted using field formatters.

The module previously did not sufficiently validate files under the scenario of a file replacement leading to multiple exploit paths including persistent Cross Site Scripting.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission to edit files.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: