Date: 
Wednesday, Feb 7th, 2018
Advisory ID: 
BACKDROP-SA-CONTRIB-2018-001
Security risk: 
Moderately Critical
Vulnerability: 
Information Disclosure
Versions affected: 
  • FileField Sources module versions prior to 1.11.0
Description: 

This module enables you to upload files to fields via several sources.

The module doesn't sufficiently handle access control under the scenario of the autocomplete path of reference sources.

Solution: 

If you use the filefield_sources module and the provided "Reference Existing" source, upgrade to the latest version of the module, 1.11.0, from the project page or via the built-in project updater within Backdrop.

Reported By: 
Fixed By: 
Coordinated By: 

Security email list

Backdrop maintains a security mailing list. Whenever a security release comes out, an email will be sent to everyone subscribed to that list, announcing the new release. Please follow the steps below to join the Security email list.

  1. Log in to backdropcms.org
  2. Edit your profile
  3. Switch to the "Subscriptions" tab
  4. Check the box labeled "Security updates"
  5. Save the form