Updates have been released for Drupal versions 7, 8.9, 9.0 and 9.1. Drupal is a PHP-written, user-friendly and powerful content management platform, with which, for example, websites can be created. It’s simple enough for a novice user, but powerful enough to build a more complex website as well. The program includes a content management platform and a development framework. The updates contain a fix for a cross-site scripting vulnerability:
Drupal core – Critical – Cross-site scripting – SA-CORE-2021-002
Project: Drupal core
security risk: Critical 15∕25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:Default
Vulnerability: Cross-site scripting
Description: Drupal core’s sanitization API fails to properly filter cross-site scripting under certain circumstances. Not all sites and users are affected, but configuration changes to prevent the exploit might be impractical and will vary between sites. Therefore, we recommend all sites update to this release as soon as possible.
Solution: Install the latest version:
- If you are using Drupal 9.1, update to Drupal 9.1.7.
- If you are using Drupal 9.0, update to Drupal 9.0.12.
- If you are using Drupal 8.9, update to Drupal 8.9.14.
- If you are using Drupal 7, update to Drupal 7.80.
Versions of Drupal 8 prior to 8.9.x are end-of-life and do not receive security coverage.
|Version number||7.80 / 8.9.14 / 9.0.12 / 9.1.7|
|Operating systems||script language|