Project:
Project machine name:
cleantalkDate:
2022-March-30
Vulnerability:
SQL Injection
Affected versions:
<4.15.0 || >=9.1.0 <9.1.21
Description:
This module provides integration with the CleanTalk spam protection service.
The module does not properly filter data in certain circumstances.
Update: 2022-03-31 - fix release node links
Solution:
Install the latest version:
- If you use the Anti Spam by CleanTalk module for Drupal 8.x, upgrade to Anti Spam by CleanTalk 8.x-4.15
- If you use the Anti Spam by CleanTalk module for Drupal 9.x, upgrade to Anti Spam by CleanTalk 9.1.21
Fixed By:
Coordinated By:
- Chris McCafferty of the Drupal Security Team
- Greg Knaddison of the Drupal Security Team