The Webform Multifile File Upload module contains a Remote Code Execution (RCE) vulnerability exists where form inputs will be unserialized and a specially crafted form input may trigger arbitrary code execution depending on the libraries available on a site.

This vulnerability is mitigated by the fact that an attacker must have the ability to submit a Webform with a Multiple File Input field. Further, a site must have an object defined with methods that are invoked at wake/destroy that include code that can be leveraged for malicious purposes (Drupal 7 Core contains one such class which can be used to delete arbitrary files).

VCS Label
6.x-1.4
Core compatibility
Release type
Packaged Git sha1
df5c0c5cabded4431b562c54266b776712c0406d
Release files
d4d16a14bca990696e51f89d7afb8290
Release file SHA-1 hash
5cdd943ef6b5c64da01808c2f85ee004c3a58d52
Release file SHA-256 hash
8078096582f0a6f1ac25184770089939955574ef4a5040ab11ba675da324a4ee
770342aad4f2187648b146b3f5870bd0
Release file SHA-1 hash
7056431817fdb7c6355395d14983a32f4011dc64
Release file SHA-256 hash
430f2c07df1ee389328fc7f75bdb18474a1685c2d67a3b6a06945c9244f5f149