Skip to main content

Drupal Multiple Vulnerabilities

Last Update Date: 23 Apr 2019 10:21 Release Date: 23 Apr 2019 4262 Views

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

Multiple vulnerabilities have been identified in Drupal. A remote user can exploit these vulnerabilities to trigger cross site scripting, security restriction bypass and remote code execution on the targeted system.


Impact

  • Cross-Site Scripting
  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • Versions prior to Drupal 8.6.15
  • Versions prior to Drupal 8.5.15

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to Drupal 8.6.15
  • Update to Drupal 8.5.15

Vulnerability Identifier


Source


Related Link