CVE-2016-3162: Debian Linux
High severity, CVSS 8.1. EPSS: 1.6% chance of exploitation in the next 30 days.
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files.
Affected products
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Drupal Drupal: version 7.0 only; version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; …
Published 2016-04-12. Last modified 2026-06-17.