Junglewise Threat Intelligence

CVE-2019-6340: Drupal Core Remote Code Execution Vulnerability

CVE-2019-6340 · Severity: critical · CVSS 3 · Exploited in the wild · Published 2022-05-13

Technologies: Drupal Core, Drupal Core. Vendors: Packagist, Drupal.

Executive brief

Drupal Core contains a remote code execution vulnerability due to improper sanitization of data from non-form sources in certain field types. An attacker can exploit this by sending malicious PATCH or POST requests to sites with RESTful Web Services or similar modules enabled, potentially leading to arbitrary PHP code execution.

Affected products

  • Drupal Drupal Core 8.5.x before 8.5.11, 8.6.x before 8.6.10

Timeline

  • 2019-02-20: disclosed: Initial advisory date based on CVE ID and early references.
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2019-03-05: exploited: Exploit code published on Exploit-DB.

Related threats