Drupal Multiple Vulnerabilities
RISK: Medium Risk
TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in Drupal Core. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, spoofing, sensitive information disclosure, remote code execution and data manipulation on the targeted system.
Impact
- Cross-Site Scripting
- Remote Code Execution
- Data Manipulation
- Information Disclosure
- Spoofing
System / Technologies affected
- Drupal version prior to 10.5.12
- Drupal version 10.6.x prior to 10.6.11
- Drupal version 11.2.x prior to 11.2.14
- Drupal version 11.3.x prior to 11.3.12
- Drupal version 11.0.*
- Drupal version 11.1.*
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- For Drupal 10.5.x, update to Drupal 10.5.12.
- For Drupal 10.6.x, update to Drupal 10.6.11.
- For Drupal 11.2.x, update to Drupal 11.2.14.
- For Drupal 11.3.x, update to Drupal 11.3.12.
Note: All versions of Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)
Vulnerability Identifier
Source
Related Link
Related Tags
Share with
