Total vulnerabilities in the database
In Drupal core, when sending email some variables were not being sanitized for shell arguments in DefaultMailSystem::mail()
, which could lead to remote code execution.
Software | From | Fixed in |
---|---|---|
![]() |
7.0 | 7.60 |
![]() |
8.0.0 | 8.5.8 |
![]() |
8.6.0 | 8.6.2 |