The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Drupal | — | Upgrade to Drupal version 7.32 | Aug 2, 2017 | Oct 15, 2014 |
| Freebsd | — | Upgrade drupal7 | Dec 10, 2025 | Oct 16, 2014 |
| Ubuntu | — | Upgrade drupal7 | Nov 19, 2024 | Oct 16, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub