Insecure Unserialize Vulnerability in Views Dynamic Fields Module for Drupal
CVE-2019-19826

8.1HIGH

Key Information:

Vendor
Drupal
Vendor
CVE Published:
16 December 2019

Summary

The Views Dynamic Fields module for Drupal is susceptible to vulnerabilities due to insecure unserialize calls, specifically in handlers/views_handler_filter_dynamic_fields.inc. This flaw can be exploited through PHP object injection, particularly involving a field_names object and an Archive_Tar object. Successful exploitation could lead to unauthorized file deletion and, in certain scenarios, may enable remote code execution, posing serious security risks to affected Drupal installations.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.