ZeroHour

CVE-2018-7602

KEV ransomware PoC ×2

Drupal Core Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
99%p100
Published
()
KEV added
Description

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.

CISA Known Exploited Vulnerability
Affected
Drupal Core
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
drupaldebian
Products
drupal, debian linux
Ecosystems
Drupal
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news