CVE-2014-5170: Drupal Storage API
Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.
The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveraging failure to update .htaccess file contents after SA-CORE-2013-003.
Affected products
- Drupal Storage API: version 7.x-1.0 only; version 7.x-1.1 only; version 7.x-1.2 only; version 7.x-1.3 only; version 7.x-1.4 only; version 7.x-1.5 only; …
Published 2018-03-29. Last modified 2026-06-17.