Vulnerability in Drupal Allow All File Extensions for file fields.This issue affects Allow All File Extensions for file fields: *.*.
References
History

Tue, 02 Sep 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Allow All File Extensions For File Fields Project
Allow All File Extensions For File Fields Project allow All File Extensions For File Fields
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:allow_all_file_extensions_for_file_fields_project:allow_all_file_extensions_for_file_fields:*:*:*:*:*:drupal:*:*
Vendors & Products Allow All File Extensions For File Fields Project
Allow All File Extensions For File Fields Project allow All File Extensions For File Fields

Fri, 31 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jan 2025 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Drupal Allow All File Extensions for file fields.This issue affects Allow All File Extensions for file fields: *.*.
Title Allow All File Extensions for file fields - Critical - Unsupported - SA-CONTRIB-2024-075
References

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2025-01-31T15:43:38.167Z

Reserved: 2025-01-09T20:26:29.340Z

Link: CVE-2024-13311

cve-icon Vulnrichment

Updated: 2025-01-10T13:50:46.404Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-09T21:15:28.970

Modified: 2025-09-02T18:29:33.600

Link: CVE-2024-13311

cve-icon Redhat

No data.