Junglewise Threat Intelligence

CVE-2018-7602: Drupal Core Remote Code Execution Vulnerability

CVE-2018-7602 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2024-04-23

Technologies: Drupal Core, Drupal Core. Vendors: Packagist, Drupal.

Executive brief

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. Attackers can exploit multiple attack vectors to compromise the site, a flaw related to the previous SA-CORE-2018-002 (Drupalgeddon 2) vulnerability.

Affected products

  • Drupal Drupal Core 7.x, 8.x (specifically < 7.59, 8.4.x < 8.4.8, 8.5.x < 8.5.3)

Timeline

  • 2018-04-25: disclosed: SA-CORE-2018-004 / CVE-2018-7602 published by Drupal.org
  • 2018-04-25: patched: Security updates released for Drupal 7.59, 8.4.8, and 8.5.3
  • 2022-04-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2018-04-25: exploited: Reported as being exploited in the wild at the time of disclosure.

Related threats