Website Security & Threat Management
Drupal 7 SA-CORE-2014-005 SQL Injection Protection

Drupal 7 SA-CORE-2014-005 SQL Injection Protection

10/16/2014 · John Graham-Cumming

What this post added

This post details the immediate mitigation of a critical SQL injection vulnerability (SA-CORE-2014-005) in Drupal 7 by updating Cloudflare's Web Application Firewall (WAF) rules. It specifically mentions Rule D0002 as providing protection and instructs users to enable the 'CloudFlare Drupal' ruleset if not already active. The post also strongly advises users to upgrade to the safe version of Drupal (7.32) or apply the patch, and provides an update on the severity of the vulnerability based on a Drupal Security Team PSA, indicating that sites not patched before a specific date should be assumed compromised.

Read the original post ↗