QID 730163

Date Published: 2021-08-31

QID 730163: Drupal Core Security Update (SA-CORE-2021-004)

Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.

Affected Versions:
Drupal 9.2.x prior to Drupal 9.2.2
Drupal 9.1.x prior to Drupal 9.1.11
Drupal 8.9.x prior to Drupal 8.9.17
Drupal 7.x prior to Drupal 7.82

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Drupal installed on the target.

Successful exploitation of these vulnerabilities could affect Confidentiality and Integrity.

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as Medium - 3.6 severity.
  • Solution
    Customers are advised to install latest drupal version.
    For more information visitDrupal security advisory SA-CORE-2021-004
    Vendor References

    CVEs related to QID 730163

    Software Advisories
    Advisory ID Software Component Link
    SA-CORE-2021-004 URL Logo www.drupal.org/sa-core-2021-004