Description
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."
Remediation
References
Related Vulnerabilities
Vanilla Forums Deserialization of Untrusted Data Vulnerability (CVE-2018-19499)
IBM RTC Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2020-4547)
WordPress Plugin Zingiri Web Shop Cross-Site Scripting (2.4.2)
WordPress Plugin Product Addons & Fields for WooCommerce Arbitrary File Upload (1.1)