Vulnerability Description
The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_Tar object, for file deletion. Code execution might also be possible.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Drupal | Views Dynamic Field | <= 6.x-1.4 |
Related Weaknesses (CWE)
References
- https://www.drupal.org/project/views_dynamic_fields/issues/3056600Vendor Advisory
- https://www.drupal.org/project/views_dynamic_fields/issues/3056600Vendor Advisory
FAQ
What is CVE-2019-19826?
CVE-2019-19826 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involvi...
How severe is CVE-2019-19826?
CVE-2019-19826 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-19826?
Check the references section above for vendor advisories and patch information. Affected products include: Drupal Views Dynamic Field.