Drupal released security updates
Drupal developers have released security updates to address cross-site scripting vulnerability affecting Drupal 7, 8.9, 9.0, and 9.1. An attacker could exploit this vulnerability to take control of an affected system.
According to Drupal security advisory, users are recommended to install the latest version:
If you are using Drupal 9.1, update to Drupal 9.1.7.
If you are using Drupal 9.0, update to Drupal 9.0.12.
If you are using Drupal 8.9, update to Drupal 8.9.14.
If you are using Drupal 7, update to Drupal 7.80.
More information on vulnerability and updates is available in Drupal security advisory – SA-CORE-2021-002.
23 April 2021