PT-2018-3600 · Drupal+1 · Drupal+1

G0Tmi1K

+1

·

Publicado

2018-03-28

·

Atualizado

2026-03-10

·

CVE-2018-7600

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Drupal versions prior to 7.58 Drupal versions 8.x prior to 8.3.9 Drupal versions 8.4.x prior to 8.4.6 Drupal versions 8.5.x prior to 8.5.1
Description The issue is related to insufficient input validation in the Drupal CMS system, allowing a remote attacker to execute arbitrary code and potentially take control of a site using a specially crafted HTTP request. This is due to a problem affecting multiple subsystems with default or common module configurations.
Recommendations For Drupal versions prior to 7.58, update to version 7.58 or later. For Drupal versions 8.x prior to 8.3.9, update to version 8.3.9 or later. For Drupal versions 8.4.x prior to 8.4.6, update to version 8.4.6 or later. For Drupal versions 8.5.x prior to 8.5.1, update to version 8.5.1 or later.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2021-00549
CVE-2018-7600
DLA-1325-1
DRUPAL-CORE-2018-002
DSA-4156-1
GHSA-7FH9-933G-885P
USN-4773-1

Produtos afetados

Drupal
Ubuntu