—
DRUPAL-CONTRIB-2023-053
Details
The Xsendfile module enables fast transfer for private files in Drupal.
In order to control private file downloads, the module overrides `ImageStyleDownloadController`, for which a vulnerability was disclosed in [SA-CORE-2023-005](https://www.drupal.org/sa-core-2023-005). The Xsendfile module was still based on an insecure version of `ImageStyleDownloadController`.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/xsendfile
Introduced in:
0Fixed in: 1.2.0Upgrade drupal/xsendfile to 1.2.0 or newer (ecosystem packagist:https://packages.drupal.org/8).