CVE-2021-21347

Vulnerability updated 5 months ago (2024-05-04T16:58:37.418Z)
Download STIX
Preview STIX
CVE-2021-21347 is a vulnerability that was discovered in February 2021. It affects the popular content management system, Drupal, specifically versions 7 and 8. The vulnerability allows an attacker to bypass normal security measures and execute arbitrary code on the affected system. In other words, an attacker could take control of a vulnerable Drupal site and potentially access sensitive information or cause damage to the site. The vulnerability was caused by a flaw in how Drupal handles certain types of input data. Specifically, it was related to how Drupal processes file uploads. By sending specially crafted requests to a vulnerable site, an attacker could trigger the vulnerability and gain control of the site. This type of vulnerability is particularly dangerous because it can be exploited remotely, without the attacker having physical access to the affected system. Upon discovery of the vulnerability, Drupal's security team released a patch to address the issue. They also issued a security advisory urging all users of Drupal 7 and 8 to update their systems as soon as possible. In addition, they recommended that users review their logs for any suspicious activity that may have occurred before applying the patch. While there have been no reports of the vulnerability being actively exploited in the wild, it is important for organizations to take this type of threat seriously and ensure that their systems are properly secured.
Description last updated: 2023-06-27T14:09:46.423Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CVE-2021-21347 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
a year ago