← back
CVE-2011-4972

CVE-2011-4972

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.7%
exploitation probability
1.7%top 24% of all CVEs
observed exploitation
nono source reports it
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.