The Drupal is warning users who run websites that are not updated to version 7 of the popular open-source content management system (CMS) that they may be at risk from automated attacks.
Attackers are trying to exploit a vulnerability in Structured Query Language (SQL) commands in Drupal, which was discovered two weeks ago. The bug has been rated as extremely critical and could affect millions of websites worldwide.
The attacks leave no trace, the Drupal , and could lead to copying and malicious use of all data from the compromised websites.
Additionally, attackers may have installed backdoors to access the website using the vulnerability. The security team warned that simply updating Drupal to version 7.32 will not remove the malicious code.
It recommended that users with insecure websites take them offline and restore backups before October 15, applying the updated version of the code.
