Drupal Core Remote Code Execution Vulnerability
Critical severity
GitHub Reviewed
Published
Apr 23, 2024
to the GitHub Advisory Database
•
Updated Jul 5, 2024
Description
Published by the National Vulnerability Database
Jul 19, 2018
Published to the GitHub Advisory Database
Apr 23, 2024
Reviewed
Apr 23, 2024
Last updated
Jul 5, 2024
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.
References