Drupal Core Multiple Security Vulnerabilities

Drupal is prone to the following security vulnerabilities:

1. An information-disclosure vulnerability
2. Multiple security-bypass vulnerabilities
3. A denial-of-service vulnerability

An attacker can exploit these issues to bypass certain security restrictions and perform unauthorized actions, obtain sensitive information and cause denial-of-service conditions, to construct a crafted URI and entice a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks.

Drupal 7.x versions prior to 7.52 and 8.x versions prior to 8.2.3 are vulnerable.


 

Privacy Statement
Copyright 2010, SecurityFocus