CVE-2024-13276

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful Browsing.This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.39.

Credits

Devin Zuczek
Devin Zuczek
Joseph Olstad
Greg Knaddison
Damien McKenna
Juraj Nemec

References