Blog | G5 Cyber Security

CVE-2019-6342 flaw allows hackers to fully compromise Drupal 8.7.4 websites

Drupal 8.7.4 is affected by a critical flaw, tracked as CVE-2019-6342, that could be exploited by attackers to take control of Drupal 8 sites. The vulnerability can be mitigated by disabling the Workspaces module. The U.S. Department of Homeland Security has also published a security update for the flaw. There is no evidence of cyber attacks exploiting the flaw in the wild, but experts believe that threat actors could start exploiting it very soon because it is easy to exploit and require minimal user interaction.”]

Source: https://securityaffairs.co/wordpress/88568/hacking/cve-2019-6342-drupal-8-7-4.html

Exit mobile version