CISA Orders Feds to Patch Drupal Flaw
CISA told federal agencies to patch a Drupal SQL injection flaw by Wednesday evening.
The vulnerability lets unauthenticated attackers trigger SQL injection on PostgreSQL-backed Drupal sites. It is actively exploited in the wild.
Affects multiple Drupal versions running on government and public web servers.
CISA added the flaw to its Known Exploited Vulnerabilities catalog last week.
