CVE-2018-7600

CRITICAL9.8⚠ KEVEPSS 94.5%

Drupal Core Remote Code Execution Vulnerability

Published: 3/28/2018Modified: 12/10/2025Added to CISA KEV: 11/3/2021
Also known as:GHSA-7fh9-933g-885pDRUPAL-CORE-2018-002

Description

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

Affected packages (5)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H

References (25)