CVE-2018-7600 – drupal/core
Package
Manager: composer
Name: drupal/core
Vulnerable Version: >=7.0 <7.58 || >=8.0 <8.3.9 || >=8.4.0 <8.4.6 || >=8.5.0 <8.5.1
Severity
Level: Critical
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.9447 pctl0.99996
Details
Drupal Core Remote Code Execution Vulnerability Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
Metadata
Created: 2022-05-14T01:29:45Z
Modified: 2024-04-23T22:36:48Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7fh9-933g-885p/GHSA-7fh9-933g-885p.json
CWE IDs: ["CWE-20"]
Alternative ID: GHSA-7fh9-933g-885p
Finding: F184
Auto approve: 1