{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/drupal-11.x-dev/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:drupal:drupal:2023-05-09:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.3,"id":"CVE-2024-45440"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Drupal (11.x-dev)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","drupal","reconnaissance"],"_cs_type":"advisory","_cs_vendors":["Drupal"],"content_html":"\u003cp\u003eCVE-2024-45440 is a security vulnerability in Drupal 11.x-dev that enables an unauthenticated attacker to perform full path disclosure. The flaw resides within the \u003ccode\u003ecore/authorize.php\u003c/code\u003e component. When the application attempts to process the \u003ccode\u003ehash_salt\u003c/code\u003e parameter, an improper execution of \u003ccode\u003efile_get_contents\u003c/code\u003e on a non-existent or misconfigured file can trigger an error response that reveals the absolute path of the Drupal installation on the underlying server. While the vulnerability is classified as medium severity (CVSS 5.3), the exposure of internal filesystem structures provides attackers with reconnaissance data that facilitates more complex, targeted attacks. Publicly available exploit scripts automate the discovery process, increasing the risk for organizations running development or pre-release versions of the Drupal core.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target server running Drupal 11.x-dev.\u003c/li\u003e\n\u003cli\u003eAttacker probes the endpoint \u003ccode\u003e/core/authorize.php\u003c/code\u003e to determine if it is reachable.\u003c/li\u003e\n\u003cli\u003eAttacker submits a specially crafted HTTP request targeting the \u003ccode\u003ehash_salt\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eThe vulnerable \u003ccode\u003ecore/authorize.php\u003c/code\u003e script triggers a \u003ccode\u003efile_get_contents\u003c/code\u003e operation on an invalid file path.\u003c/li\u003e\n\u003cli\u003eThe application fails to handle the error properly, generating an error log that includes the full server-side path.\u003c/li\u003e\n\u003cli\u003eThe server returns the path information in the HTTP response body to the attacker.\u003c/li\u003e\n\u003cli\u003eAttacker uses the disclosed path information to plan further reconnaissance or exploit attempts against the server infrastructure.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the leakage of sensitive internal filesystem paths. While not providing direct remote code execution, this information disclosure is a critical reconnaissance step. It allows adversaries to map server directory structures, facilitating the identification of configuration files, backup files, or other sensitive resources that could be targeted in secondary attacks. The vulnerability affects Drupal 11.x-dev versions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify and upgrade all instances of Drupal 11.x-dev to a patched, stable release that remediates this disclosure flaw.\u003c/li\u003e\n\u003cli\u003eRestrict public access to administrative and installation-related scripts, specifically \u003ccode\u003ecore/authorize.php\u003c/code\u003e, if they are not required for normal site operation.\u003c/li\u003e\n\u003cli\u003eDeploy the webserver-level detection rule below to monitor for exploitation attempts against the \u003ccode\u003eauthorize.php\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eReview web access logs for 200/500 status codes originating from suspicious query strings containing \u003ccode\u003ehash_salt\u003c/code\u003e.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T16:37:18Z","date_published":"2026-10-02T16:37:18Z","id":"https://feed.craftedsignal.io/briefs/2026-10-drupal-path-disclosure/","summary":"CVE-2024-45440 is a full path disclosure vulnerability in Drupal 11.x-dev allowing unauthenticated attackers to leak server-side filesystem paths via the authorize.php endpoint.","title":"Full Path Disclosure Vulnerability in Drupal 11.x-dev","url":"https://feed.craftedsignal.io/briefs/2026-10-drupal-path-disclosure/"}],"language":"en","title":"CraftedSignal Threat Feed - Drupal (11.x-Dev)","version":"https://jsonfeed.org/version/1.1"}