Drupal Multiple Vulnerabilities
RISK: Medium Risk
TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in Drupal Core. A remote attacker could exploit these vulnerabilities to trigger cross-site scripting, remote code execution and security restriction bypass on the targeted system.
Impact
- Cross-Site Scripting
- Remote Code Execution
- Security Restriction Bypass
System / Technologies affected
- Drupal version prior to 10.3
- Drupal version prior to 10.4
- Drupal version prior to 11.0
- Drupal version prior to 11.1
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- For Drupal 10.3, update to Drupal 10.3.13.
- For Drupal 10.4, update to Drupal 10.4.3.
- For Drupal 11.0, update to Drupal 11.0.12.
- For Drupal 11.1, update to Drupal 11.1.3.
Note: All versions of Drupal 10 prior to 10.3 are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with