Vulnerability DRUPAL-CONTRIB-2026-217

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
11 hours ago
October 07, 2026 at 04:58 PM UTC
No summary available

Details

Advanced File System turns Drupal's file storage into a manageable, observable and maintainable subsystem.

The Advanced Filesystem: Backup submodule does not sufficiently validate certain requests. This may allow an attacker to trick an authenticated user into performing unintended actions through a Cross-Site Request Forgery (CSRF) vulnerability.

The vulnerability is mitigated by the fact that advanced_filesystem_backup module must be enabled.

Timeline

Published
11 hours ago
October 07, 2026 at 04:58 PM UTC
Last Modified
7 hours ago
October 07, 2026 at 08:15 PM UTC