V-Help
← All news
Security

CISA Urges Immediate Fix for Drupal Vulnerability Exploited by Hackers

CISA Urges Immediate Fix for Drupal Vulnerability Exploited by Hackers

Photo: BleepingComputer

Quick answer

CISA требует срочно устранить критическую SQL-инъекцию в Drupal, эксплуатируемую хакерами. Федеральные ведомства США должны установить патчи до среды.

The US Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to address a critical vulnerability in the Drupal platform that is actively being exploited by malicious actors. The issue involves a severe SQL injection flaw that allows unauthorized access to website databases.

According to CISA’s directive, all government agencies must apply patches by the end of the workday on Wednesday. The vulnerability affects Drupal versions widely used for corporate and government websites. Security experts warn that successful exploitation could lead to data breaches or full server compromise.

Drupal is a popular CMS alongside WordPress and Joomla, frequently used by large organizations. Security specialists advise all platform users, regardless of location, to update their systems immediately to the latest secure version to prevent potential attacks.

Common questions

Какую уязвимость CISA требует устранить в Drupal?
CISA требует устранить критическую SQL-инъекцию, которая позволяет хакерам получать несанкционированный доступ к базам данных сайтов, работающих на Drupal.
Кто должен устранить уязвимость в Drupal по требованию CISA?
Требование CISA распространяется на федеральные ведомства США, которые обязаны установить патчи до конца рабочего дня в среду.
Какие последствия может иметь эксплуатация уязвимости в Drupal?
Успешная эксплуатация уязвимости может привести к утечке конфиденциальной информации или полному захвату контроля над сервером.
Какие версии Drupal уязвимы к атаке?
Уязвимость затрагивает широко используемые версии Drupal, которые применяются для создания корпоративных и правительственных веб-ресурсов.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: BleepingComputer