Drupal Devel Module Script Insertion - Security Advisory

Posted by: Admin

Tagged in: vulnerability , script , module , insertion , drupal

security warning

This Security Advisory is delivered as a service by Hanzo Host to help our customers
and friends keep their systems up-to-date against the latest vulnerabilities.

Security Advisory

Drupal Devel Module Script Insertion Vulnerability

Info:

A vulnerability has been reported in the Devel module for Drupal which can be exploited to conduct script insertion attacks.

The vulnerability is reported in versions prior to 5.x-1.2 and 6.x-1.18.

Solution:

Update your site to the latest version.

An one-click update is available to Hanzo Host customers within your account. Please update your install as soon as possible via your cPanel:

1.) log in to cPanel
2.) scroll down the page to
Software / Services > Installatron Applications Installer

3.) Available updates are highlighted
4.) Click on the options you wish to update

 

If you have any questions please contact Support by raising a ticket via the Customer Portal

Many thanks!