- Tablefield 2.5.x versions prior to 2.5.4
The tablefield module allows you to attach tabular data to an entity.
The module doesn't sufficiently determine that the data being unserialized is the contents of a tablefield when users request a CSV export, which could lead to Remote Code Execution via Object Injection.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission 'export tablefield', and be able to insert a payload into an entity's field.
Upgrade to the most recent version of the Tablefiield module. Download available on the Tablefield 1.x-2.5.4 release page. See the update instructions, if needed.
- Drew Webber, Provisional Drupal Security Team Member
- Drew Webber, Provisional Drupal Security Team Member
- Martin Postma
- Jen Lampton of the Backdrop CMS Security Team
- Greg Knaddison of the Drupal Security Team