SA-CORE-2025-007: Critical severity Drupal Drupal vulnerability
By generating and tricking a user into visiting a malicious URL, an attacker can perform site defacement. The defacement is not stored and is only present when the URL has been crafted for that purpose. Only the defacement is present, so no other site content (such as branding) is rendered.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of SA-CORE-2025-007?
The severity of SA-CORE-2025-007 is considered critical due to its potential for site defacement.
How do I fix SA-CORE-2025-007?
To fix SA-CORE-2025-007, upgrade your Drupal installation to versions 10.4.10, 10.5.7, 11.1.10, or 11.2.9 or later.
Who is affected by SA-CORE-2025-007?
SA-CORE-2025-007 affects users running Drupal versions up to 10.4.9, 10.5.6, 11.1.9, and 11.2.8.
What kind of attack does SA-CORE-2025-007 facilitate?
SA-CORE-2025-007 facilitates site defacement through crafted malicious URLs.
Is the defacement caused by SA-CORE-2025-007 permanent?
No, the defacement caused by SA-CORE-2025-007 is not stored and only occurs when the specific URL is visited.