CVE-2012-0827: Drupal

Low severity, CVSS 3.5. EPSS: 1.3% chance of exploitation in the next 30 days.

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

Affected products

  • Drupal Drupal: version 7.0 only; version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; …

Published 2013-10-28. Last modified 2026-06-16.