logo

CVE-2018-7600 drupal/core

Package

Manager: composer
Name: drupal/core
Vulnerable Version: >=7.0 <7.58 || >=8.0 <8.3.9 || >=8.4.0 <8.4.6 || >=8.5.0 <8.5.1

Severity

Level: Critical

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.9447 pctl0.99996

Details

Drupal Core Remote Code Execution Vulnerability Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

Metadata

Created: 2022-05-14T01:29:45Z
Modified: 2024-04-23T22:36:48Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7fh9-933g-885p/GHSA-7fh9-933g-885p.json
CWE IDs: ["CWE-20"]
Alternative ID: GHSA-7fh9-933g-885p
Finding: F184
Auto approve: 1