drupal/core is vulnerable to SQL Injection
98
Critical Risk
Drupal core's database abstraction API does not sufficiently prevent SQL injection in some PostgreSQL query handling. An anonymous attacker can send specially crafted requests that result in arbitrary SQL injection on affected PostgreSQL-backed sites. Pre-fix sites can expose non-public data, allow privilege escalation, remote code execution, or other database-driven compromise. The fix updates Drupal core's database handling and ships in the listed security releases.
You are affected if you are using a version that falls within the vulnerable range and your site uses PostgreSQL.
drupal/core is vulnerable to SQL Injection in versions 8.9.0 - 10.4.9, 10.5.0 - 10.5.9, 10.6.0 - 10.6.8, 11.0.0 - 11.1.9, 11.2.0 - 11.2.11 and 11.3.0 - 11.3.9.
Upgrade the drupal/core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant