Critical Remote Code Execution Vulnerabilities Patched by Drupal
#1
Quote:Drupal patched two critical remote code execution vulnerabilities which would have allowed attackers to exploit Drupal CMS installations with versions prior to 7.60, 8.6.2, and 8.5.8.

The first critical vulnerability resided in Drupal's DefaultMailSystem::mail() mailing component and it leads to RCE when sent emails contain variables which were not sanitized for shell arguments. The second critical security issue patched by Drupal was present in the Contextual Links module which did not sufficiently validate requested contextual links.
"This vulnerability is mitigated by the fact that an attacker must have a role with the permission "access contextual links," according to Drupal's SA-CORE-2018-006 security advisory.

Source: https://news.softpedia.com/news/critical...3315.shtml
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Critical Remote Code Execution Vulnerabilities Patched by Drupal - by silversurfer - 19 October 18, 13:30

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Thunderbird 151.0 & 140.11.0esr
Thunderbird 151.0 ...harlan4096 — 07:23
Waterfox 6.6.13
Waterfox 6.6.13 ...harlan4096 — 06:14
Subscription security: how to protect yo...
Why subscription o...harlan4096 — 06:10
Mozilla Firefox Browser 151.0
Mozilla Firefox Br...harlan4096 — 06:09
Tor Browser 15.0.14
Tor Browser 15.0.1...harlan4096 — 06:07

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)axuben
avatar (40)ihijudu
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>