HomeSecurityVulnerability allows SQL injection in Drupal websites

Vulnerability allows SQL injection in Drupal websites

drupal

The Drupal 7 core is vulnerable to a “Highly Critical” (as the developers describe it) vulnerability that allows an attacker to gain access to the website using SQL injection.

The Drupal security team reports that versions of the Drupal 7 software prior to version 7.32 are vulnerable to a high-critical vulnerability that allows SQL injections. The immediately released version 7.32 is available to address the bug, and the CMS team recommends that all administrators of this CMS update their websites immediately. The platform is a popular content management system (CMS) that is usually available for free and is open source.

An attacker who could exploit this vulnerability could gain administrator privileges or execute arbitrary PHP code. The attack can be initiated by an anonymous user, which means that no social engineering or other techniques are required to initiate the attack.

The company's security team recommends that all sites install the latest version. If administrators don't want to change all the php files, there is a simple patchthat will close the security gap.

The vulnerability exists in the database abstraction API, one of the purposes of which is to
"sanitize" database requests from this type of attack.

The vulnerability was discovered by Sektion Eins, a German PHP security firm that was hired to audit the platform by an anonymous client. The bug has been named CVE-2014-3704.

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS