Security News

All Drupal Versions Susceptible to Code Execution, Credential Theft Vulnerabilities (Threatpost)
2016-01-06 21:34

A number of issues exist in the content management system Drupal that could lead to code execution and the theft of database credentials via a man-in-the-middle attack, a researcher warns.

Pair of Drupal Modules Patch Access Bypass Flaws (Threatpost)
2015-09-10 14:36

A pair of modules included in the Drupal content management system have been updated to fix access bypass vulnerabilities that could allow an attacker to take actions on the behalf of some users....

Several Critical Flaws Patched in Drupal Module (Threatpost)
2015-07-23 17:27

There are several critical vulnerabilities in a middleware layer used in Drupal, including both cross-site scripting and cross-site request forgery bugs, that can be exploited remotely. The...