Drupal warns of mass SQL injection website hacks
The security team for Drupal project is warning users that websites running unpatched installations of version 7 of the popular open source content management system (CMS) may be compromised by automated attacks.
"You should proceed under the assumption that every Drupal 7 website was compromised unless updated or patched before Oct 15, 11pm UTC, that is 7 hours after the announcement," the security team said.
Attackers are presently attempting to exploit a Structured Query Language (SQL) command and data injection flaw in Drupal that was discovered two weeks' ago. The flaw is rated as highly critical, scored 25 of a possible 25 by the group's own risk matrix, and may affect hundreds of thousands of websites around the world.