Fancy File Delete - Moderately critical - Access Bypass - SA-CONTRIB-2022-023
Project: Fancy File Delete
Date: 2022-February-09
Security risk: Moderately critical 14∕25
Vulnerability: Access Bypass
Description
This module enables you to manage and delete files.
The module doesn't sufficiently protect unmanaged files from view under the scenario unauthenticated user knows path to visit the view and can attempt to delete files which results in duplicate files being created.