Drupal fixes 2 critical code execution issues flaws in Drupal 7, 8.5 and 8.6Security Affairs


Drupal released security updates for Drupal 7, 8.5 and 8.6 that address two “critical” security vulnerabilities that could be exploited for arbitrary code execution. The first vulnerability could be exploited by a remote attacker to execute arbitrary PHP code. The flaw resides in the phar stream wrapper implemented in PHP and is related to the way it handles untrusted phar:// URIs.


Source: https://securityaffairs.co/wordpress/80001/security/drupal-critical-flaws.html


Read more on this website >>