QID 730058
Date Published: 2021-04-29
QID 730058: Drupal Core Cross-Site Scripting Vulnerability(SA-CORE-2021-002)
Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.
Affected Versions:
Drupal 9.1, prior to Drupal 9.1.7.
Drupal 9.0, prior to Drupal 9.0.12.
Drupal 8.9, prior to Drupal 8.9.14.
Drupal 7, prior to Drupal 7.80.
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.
Note: Versions of Drupal 8 prior to 8.9.x are end-of-life and do not receive security coverage.
Successful exploitation of these vulnerabilities could affect Confidentiality, Integrity and Availability.
Solution
Customers are advised to install latest drupal version.
For more information visitDrupal security advisory SA-CORE-2021-002
For more information visitDrupal security advisory SA-CORE-2021-002
Vendor References
- SA-CORE-2021-002 -
www.drupal.org/sa-core-2021-002
CVEs related to QID 730058
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SA-CORE-2021-002 |
|