Multiple vulnerabilities were identified in Drupal Core. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, spoofing, sensitive information disclosure, remote code execution and data manipulation on the targeted system. Impact Cross-Site Scripting Remote Code Execution Data Manipulation Information Disclosure Spoofing System / Technologies affected Drupal version prior to 10.5.12 Drupal version 10.6.x prior to 10.6.11 Drupal version 11.2.x prior to 11.2.14 Drupal version 11.3.x prior to 11.3.12 Drupal version 11.0.* Drupal version 11.1.* Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: For Drupal 10.5.x, update to Drupal 10.5.12. For Drupal 10.6.x, update to Drupal 10.6.11. For Drupal 11.2.x, update to Drupal 11.2.14. For Drupal 11.3.x, update to Drupal 11.3.12. Note: All versions of Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)
Multiple vulnerabilities in Drupal Core, including cross-site scripting, remote code execution, and data manipulation, can be exploited by a remote attacker. Affected versions are Drupal 10 prior to 10.5.12, 10.6.x prior to 10.6.11, 11.2.x prior to 11.2.14, and 11.3.x prior to 11.3.12, while Drupal 11.0.x and 11.1.x are end-of-life and unsupported. The solution is to apply the vendor's fixes by updating to Drupal 10.5.12, 10.6.11, 11.2.14, or 11.3.12 respectively.