Drupal core vulnerable to improper error handling
Moderate severity
GitHub Reviewed
Published
Dec 5, 2024
to the GitHub Advisory Database
•
Updated Dec 5, 2024
Description
Published by the National Vulnerability Database
Dec 5, 2024
Published to the GitHub Advisory Database
Dec 5, 2024
Reviewed
Dec 5, 2024
Last updated
Dec 5, 2024
Under certain uncommon site configurations, a bug in the CKEditor 5 module can cause some image uploads to move the entire webroot to a different location on the file system. This could be exploited by a malicious user to take down a site.
The issue is mitigated by the fact that several non-default site configurations must exist simultaneously for this to occur.
References