Drupal core contains a chain of methods that could be exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget chain" presents no direct threat, but is a vector that can be used to achieve remote code execution or SQL injection if the application deserializes untrusted data due to another vulnerability.
This issue is not directly exploitable.
This issue is mitigated by the fact that in order for it to be exploitable, a separate vulnerability must be present to allow an attacker to pass unsafe input to unserialize().
Install the latest version:
Drupal 11
- If you use Drupal 11.3.x, update to .
Drupal 10
- If you use Drupal 10.6.x, update to .
Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do not receive security coverage. ( have both reached end-of-life.)
- of the Drupal Security Team
- of the Drupal Security Team
- of the Drupal Security Team
- of the Drupal Security Team
- of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
SOCIAL SHARE CARD GENERATOR