Junglewise Threat Intelligence

CVE-2018-7600: Drupal Core Remote Code Execution Vulnerability

CVE-2018-7600 · Severity: critical · CVSS 3 · Exploited in the wild · Published 2022-05-14

Technologies: Drupal Core, drupal/core (Packagist). Vendors: Drupal, Packagist.

Executive brief

Drupal Core contains a remote code execution vulnerability due to improper input validation in multiple subsystems. An unauthenticated remote attacker can exploit this to execute arbitrary code and achieve complete site compromise.

Affected products

  • Drupal Drupal Core before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1

Timeline

  • 2018-03-28: advisory: Drupal security advisory SA-CORE-2018-002 published.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats