Drupal sites vulnerable to double-extension attacks

The team behind the Drupal content management system (CMS) has released security updates to patch a critical vulnerability that can grant attackers full control over vulnerable sites.
Source: cyware.com