Drupal Multiple Vulnerabilities
RISK: Medium Risk
TYPE: Servers - Other Servers
Multiple vulnerabilities were identified in Drupal Core. A remote attacker could exploit these vulnerabilities to trigger cross-site scripting, remote code execution, security restriction bypass and data manipulation on the targeted system.
Impact
- Cross-Site Scripting
- Remote Code Execution
- Security Restriction Bypass
- Data Manipulation
System / Technologies affected
- Drupal version prior to 7.102
- Drupal version prior to 10.2.11
- Drupal version prior to 10.3.9
- Drupal version prior to 11.0.8
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- For Drupal 7, update to Drupal 7.102
- For Drupal 10.2, update to Drupal 10.2.11
- For Drupal 10.3, update to Drupal 10.3.9
- For Drupal 11.0, update to Drupal 11.0.8
Note: All versions of Drupal 10 prior to 10.2 are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Related Tags
Share with