Sunday, March 26, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

Drupal vulnerability could allow attackers to take over the system

Kiratas by Kiratas
March 19, 2023
in World
Reading Time: 1 min read
0
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter

There is a security hole in the Drupal content management system that allows attackers to take control of vulnerable systems. The US cyber security authority CISA is currently warning of this. Updated software to patch the vulnerability is available.

The vulnerability allows access restrictions to be circumvented and affects several Drupal versions, summarizes the CISA in a warning message. Administrators and users of Drupal should apply the necessary updates, the authority advises.

Drupal: Angriffsvektor Cross-Site-Scripting

The vulnerability is based on the fact that the Drupal core provides a page with the extensive information that phpinfo() throws out. This is used to diagnose the PHP system configuration. While it is not directly accessible, attackers could gain access to the information if they could run a cross-site scripting attack against users with elevated privileges.

The vulnerability has not yet received a CVE entry. The Drupal project rates the vulnerability as a moderate risk. However, updated software versions of the CMS seal the security leak. For Drupal 10.0 this is version 10.0.5, for Drupal 9.5 version 9.5.5, for Drupal 9.4 version 9.4.12 and for Drupal 7 version 7.95. The developers point out that all versions of Drupal 9 prior to 9.4 have reached end-of-life and will no longer receive security updates. Drupal 8 has also reached its end of life. If necessary, IT managers should update to a supported Drupal version and apply the available updates in a timely manner.

Last November, the Drupal project had to close vulnerabilities that made websites created with it vulnerable. Attackers could have accessed unauthorized data that was actually isolated.

(dmk)

To home page

Tags: AttackersCISACMSDrupalSecuritySecurity UpdatessystemVulnerabilitiesvulnerability

Related Posts

World

Ödegaard: “Haaland is the best striker in the world”

by Kiratas
March 26, 2023
World

At least 26 dead after tornadoes in the state of Mississippi

by Kiratas
March 26, 2023
World

The OK and KO of Sunday, March 26, 2023

by Kiratas
March 25, 2023
World

De la Fuente: “Joselu has earned everything he has achieved”

by Kiratas
March 25, 2023
World

Joselu: “I can’t believe it, this is the best”

by Kiratas
March 25, 2023
Next Post

Yolanda Díaz on whether Sumar will be in 28M: "I am going to make one of the most important decisions of my life"

Piqué charges against Shakira again in his last interview: "I'm not going to spend money..."

Docker Hub: Clarification on the deletion of Docker Free Team

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.
Contact Us:
[email protected]

Categories

  • Automobile
  • Business
  • Sports
  • World

Browse by Tag

Apple Artificial Intelligence Bank business ChatGPT Check Cybercrime data data protection day Energy EU euros February Google government health iOS iPhone law League Linux and Open Source live Mac Madrid March Microsoft million online photo price result Security Smartphone Software Development Spain Spanish Sánchez Test time today Vulnerabilities world year years

Recent Posts

  • Ödegaard: “Haaland is the best striker in the world”
  • At least 26 dead after tornadoes in the state of Mississippi
  • The OK and KO of Sunday, March 26, 2023
  • DMCA
  • Home

© Kiratas 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Kiratas 2023. All Rights Reserved.