Skip to main content

CVE-2014-3704

CVSS Score Not Available
94.37%
HIGH RiskEPSS (100th percentile)

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

Published: 10/16/2014
Modified: 4/12/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

94.37%HIGH Exploitation Risk
100th percentile

This vulnerability has a 94.37% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.