Drupal 7.24 and 6.29 have been released to address a number of security holes. Users are advised to update their installations as soon as possible.
According to the developers, the updates have been released solely to fix the vulnerabilities. There are no new features or non-security-related bug fixes.
Multiple vulnerabilities exist because of an issue with the cross-site request forgery (CSRF) protection. By leveraging the security holes in some contributed modules, …