Skip to main content

Drupal Releases Security Updates

Report a cyber attack: call 0300 303 5222 or email [email protected]

Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Drupal has released security updates to address multiple cross-site scripting (XSS)  vulnerabilities that could affect versions 7, 9.2.x, and 9.3.x. An attacker could exploit these vulnerabilities to take control of an affected system.


Remediation advice

Affected organisations are encouraged to review Drupal Security Advisories SA-CORE-2022-001 and SA-CORE-2022-002 and apply the necessary updates.



CVE Vulnerabilities

Last edited: 21 January 2022 2:27 pm