CKEditor Upload Image - Critical - Access bypass - SA-CONTRIB-2018-014

Project: CKEditor Upload Image
Date: 2018-February-21
Security risk: *Critical* 15∕25
Vulnerability: Access bypass


This module enables you to drag and drop or paste images into CKEditor.
The module does not sufficiently verify users permissions, which leads to
anonymous users being able to upload files to the server.

Install the latest version:

* If you use the CKEditor Upload Image module for Drupal 8.x, upgrade to
CKEditor Upload Image 8.x-1.5

