Arbitrary File Deletion Vulnerability in Spider Video Player Module for Drupal

Arbitrary File Deletion Vulnerability in Spider Video Player Module for Drupal

CVE-2015-4351 · MEDIUM Severity

AV:N/AC:M/AU:S/C:N/I:P/A:P

The Spider Video Player module for Drupal allows remote authenticated users with the "access Spider Video Player administration" permission to delete arbitrary files via a crafted URL.

Learn more about our User Device Pen Test.