Jump to content
Nytro

Drupal 6.37 and 7.39 released, critical vulnerabilities addressed

Recommended Posts

Posted

Drupal 6.37 and 7.39 released, critical vulnerabilities addressed

Robert Abel, Content Coordinator

Open source content management (CMS) platform Drupal has issued security patches to address several critical vulnerabilities affecting Drupal 6 and 7.

According to the Wednesday advisory, versions of Drupal prior to 6.37 and 7.39 contain three vulnerabilities, including a cross-site scripting bug in the Autocomplete system, a cross-site request forgery bug in Form API, and an information disclosure flaw in Access system.

The cross-site forgery vulnerability located in Form API “could allow a malicious user to upload files to the site under another user's account,” the advisory said.

Vulnerable versions of Drupal 7 are affected by two additional issues, including a cross-site scripting bug in the Ajax system and a SQL injection vulnerability in Database API.

The SQL injection vulnerability can enable a “user with elevated permissions to inject malicious code in SQL comments,” the advisory said.

Sursa: Drupal 6.37 and 7.39 released, critical vulnerabilities addressed - SC Magazine

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...