GITHUBEXPLOIT

drupal-sa-core-2026-004-lab_108B5C3B-AD91-501B-9F9D-A7F4DC457879

Description

SA-CORE-2026-004 — Lab, PoC, and Post-mortem Drupal core SQL injection via Entity Query condition value array keys. Disclosed 2026-05-20 17:00 UTC. Highly critical 20/25. PostgreSQL-backed Drupal installs reachable through JSON:API filters, REST views,...
Visit Original Source

Basic Information

ID 108B5C3B-AD91-501B-9F9D-A7F4DC457879
Published May 20, 2026 at 18:38

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.