security vulnerability

We encourage users to post events happening in the community to the community events group on https://www.drupal.org.
pfortuna's picture

Security Alert: Drupal Context module

A researcher has uncovered a potentially serious vulnerability in the open-source content management system used by the White House website and thousands of other sites.

The XSS, or cross-site scripting, bug resides in the Drupal Context module, a plug-in that Whitehouse.gov and about 10,000 other sites use to manage how content is viewed on their sites. According to an advisory published Monday by researcher Justin Klein Keane, the flaw allows attackers to inject malicious scripts into login pages that will reset the site's administrative password.

Read more
Subscribe with RSS Syndicate content