Description
Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: from 0.0.0 before 1.9.0, from 2.0.0 before 2.0.1.
Problem types
Product status
0.0.0 (semver) before 1.9.0
2.0.0 (semver) before 2.0.1
Credits
Willem Drupal enthousiast (willempje2)
Shelane French (shelane)
Willem Drupal enthousiast (willempje2)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
Jess (xjm)
References
www.drupal.org/sa-contrib-2025-089