CVE-2018-7600
Summary
| CVE | CVE-2018-7600 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-29 07:29:00 UTC |
| Updated | 2019-03-01 18:04:00 UTC |
| Description | Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations. |
Risk And Classification
EPSS: 0.999930000 probability, percentile 0.999860000 (date 2026-07-21)
CISA KEV: Listed on 2021-11-03; due 2022-05-03; ransomware use Known
Problem Types: CWE-20
CISA Known Exploited Vulnerability
| Vendor | Drupal |
|---|---|
| Product | Drupal Core |
| Name | Drupal Core Remote Code Execution Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2018-7600 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Drupal | Drupal | All | All | All | All |
| Application | Drupal | Drupal | All | All | All | All |
| Application | Drupal | Drupal | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit) - PHP remote Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Uncovering Drupalgeddon 2 - Check Point Research | MISC | research.checkpoint.com | Exploit, Third Party Advisory |
| Over 100,000 Drupal websites vulnerable to Drupalgeddon 2 (CVE-2018-7600) | Bad Packets Report | MISC | badpackets.net | Third Party Advisory |
| Debian -- Security Information -- DSA-4156-1 drupal7 | DEBIAN | www.debian.org | Third Party Advisory |
| GitHub - a2u/CVE-2018-7600: ????Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002 | MISC | github.com | Third Party Advisory |
| Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002 | Drupal.org | CONFIRM | www.drupal.org | Vendor Advisory |
| Any Exploit Code For "CVE-2018-7600" | MISC | greysec.net | Issue Tracking, Third Party Advisory |
| [SECURITY] [DLA 1325-1] drupal7 security update | MLIST | lists.debian.org | Third Party Advisory |
| JavaScript is not available. | MISC | twitter.com | Third Party Advisory |
| Drupal Core CVE-2018-7600 Multiple Remote Code Execution Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| GitHub - g0rx/CVE-2018-7600-Drupal-RCE: CVE-2018-7600 Drupal RCE | MISC | github.com | Patch, Third Party Advisory |
| Remote Code Execution with Drupal core (SA-CORE-2018–002) | MISC | blog.appsecco.com | Third Party Advisory |
| FAQ about SA-CORE-2018-002 | Drupal Groups | CONFIRM | groups.drupal.org | Vendor Advisory |
| JavaScript is not available. | MISC | twitter.com | Third Party Advisory |
| Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC) - PHP webapps Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Drupal Core Vulnerability CVE-2018-7600 Patch | Tenable® | MISC | www.tenable.com | Third Party Advisory |
| Synology Inc. | CONFIRM | www.synology.com | Third Party Advisory |
| Drupal Form API Flaw Lets Remote Users Execute Arbitrary Code on the Target System - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| aran na Twitterze: "The CVE is (obviously) coy about the actual exploit, but there's one subsystem that has been there for some ~12 years, relatively slow to change, and uses "#" as a control character in array keys. So it's a reasonable guess that the Render API is involved." | MISC | twitter.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.