Drupal — система управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 988
GHSA-fvm9-qc7j-544c
Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.
GHSA-vfw4-2ffw-69gw
The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks."
GHSA-jp2q-xrh4-4hph
SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows remote attackers to execute arbitrary SQL commands via an SQL comment.
GHSA-p745-347h-hjfw
Drupal sensitive information disclosure
GHSA-66gr-xrcf-8jpq
Drupal Open Redirect
GHSA-v6gx-89ww-chv2
Cross-site request forgery (CSRF) vulnerability in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for Drupal allows remote attackers to hijack the authentication of administrative users for requests that unblock a user.
GHSA-gxxq-fhc7-3jv9
Drupal Cross-Site Request Forgery (CSRF)
GHSA-c4r4-g84r-h43r
SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to a "previously cast vote."
GHSA-2qh8-6qgx-5jf9
Cross-site scripting (XSS) vulnerability in the stock quotes page in Stock 6.x before 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-p6w6-6v99-r2gr
The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-fvm9-qc7j-544c Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag. | 1% Низкий | больше 3 лет назад | ||
GHSA-vfw4-2ffw-69gw The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks." | 0% Низкий | больше 3 лет назад | ||
GHSA-jp2q-xrh4-4hph SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows remote attackers to execute arbitrary SQL commands via an SQL comment. | 14% Средний | больше 3 лет назад | ||
GHSA-p745-347h-hjfw Drupal sensitive information disclosure | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-66gr-xrcf-8jpq Drupal Open Redirect | CVSS3: 6.8 | 0% Низкий | больше 3 лет назад | |
GHSA-v6gx-89ww-chv2 Cross-site request forgery (CSRF) vulnerability in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for Drupal allows remote attackers to hijack the authentication of administrative users for requests that unblock a user. | 0% Низкий | больше 3 лет назад | ||
GHSA-gxxq-fhc7-3jv9 Drupal Cross-Site Request Forgery (CSRF) | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-c4r4-g84r-h43r SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to a "previously cast vote." | 0% Низкий | больше 3 лет назад | ||
GHSA-2qh8-6qgx-5jf9 Cross-site scripting (XSS) vulnerability in the stock quotes page in Stock 6.x before 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-p6w6-6v99-r2gr The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу