AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-6921

MEDIUM · CVSS 5.9 EPSS 1.83%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-01-15 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.9. See the original NVD description below for full technical details.

CVE
CVE-2017-6921
Severity
MEDIUM
CVSS
5.9
EPSS
1.83%

Original NVD Description

In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if the site has the RESTful Web Services (rest) module enabled, the file REST resource is enabled and allows PATCH requests, and an attacker can get or register a user account on the site with permissions to upload files and to modify the file resource.

Related CVEs

Other vulnerabilities affecting the same vendor(s)