Menu
Three popular Drupal modules get patches for site takeover flaws

Three popular Drupal modules get patches for site takeover flaws

The vulnerabilities could allow attackers to execute rogue PHP code on web servers

The security team of the popular Drupal content management system worked with the maintainers of three third-party modules to fix critical vulnerabilities that could allow attackers to take over websites.

The flaws allow attackers to execute rogue PHP code web servers that host Drupal websites with the RESTWS, Coder or Webform Multiple File Upload modules installed. These modules are not part of Drupal's core, but are used by thousands of websites.

The RESTWS module is a popular tool for creating Rest application programming interfaces (APIs) and is currently installed on over 5,800 websites. Unauthenticated attackers can exploit the remote code execution vulnerability in its page callback functionality by sending specially crafted requests to the website.

There is no mitigating factor and upgrading to the module's latest version, which fixes the flaw, is highly recommended.

Coder is another popular module and allows Drupal administrators to check their code against various coding standards and best practices. It is installed on over 4,950 websites and it too contains a remote code execution vulnerability that can be exploited by unauthenticated attackers.

The module does not even need to be enabled in order for the flaw to be exploitable, its mere presence on the file system being enough.

Finally, the Webform Multiple File Upload module allows website administrators to receive multiple files from users and is installed on some 3,000 websites. It too has a vulnerability that could lead to remote code execution, but the flaw's exploitation depends on which libraries are available on  the website.

Furthermore, an attacker needs to be able to submit a web form with specifically crafted input and, depending on the site configuration, this might require authentication. Since there are mitigating factors that could limit the flaw's impact, it was rated only as critical instead of highly critical.

The Drupal CMS powers over one million websites, including 1 in 10 of the most popular 10,000 websites on the Internet that are based on a known content management system. It is commonly used by businesses.


Follow Us

Join the newsletter!

Error: Please check your email address.

Featured

Slideshows

Kiwi channel closes 2017 with After Hours

Kiwi channel closes 2017 with After Hours

The channel in New Zealand came together to celebrate the close of 2017, as the final After Hours played out in front of a bumper Auckland crowd.

Kiwi channel closes 2017 with After Hours
Meet the top performing HP partners in NZ

Meet the top performing HP partners in NZ

HP honoured leading partners across the channel at the Partner Awards 2017 in New Zealand, recognising excellence across the entire print and personal systems portfolio.

Meet the top performing HP partners in NZ
Tech industry comes together as Lexel celebrates turning 30

Tech industry comes together as Lexel celebrates turning 30

Leading figures within the technology industry across New Zealand came together to celebrate 30 years of success for Lexel Systems, at a milestone birthday occasion at St Matthews in the City.​

Tech industry comes together as Lexel celebrates turning 30
Show Comments