{"api_version":"1","generated_at":"2026-07-23T08:56:54+00:00","cve":"CVE-2018-7600","urls":{"html":"https://cve.report/CVE-2018-7600","api":"https://cve.report/api/cve/CVE-2018-7600.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-7600","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-7600"},"summary":{"title":"CVE-2018-7600","description":"Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.","state":"PUBLIC","assigner":"security@drupal.org","published_at":"2018-03-29 07:29:00","updated_at":"2019-03-01 18:04:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://www.exploit-db.com/exploits/44482/","name":"44482","refsource":"EXPLOIT-DB","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit) - PHP remote Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://research.checkpoint.com/uncovering-drupalgeddon-2/","name":"https://research.checkpoint.com/uncovering-drupalgeddon-2/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Uncovering Drupalgeddon 2 - Check Point Research","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/","name":"https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/","refsource":"MISC","tags":["Third Party Advisory"],"title":"Over 100,000 Drupal websites vulnerable to Drupalgeddon 2 (CVE-2018-7600) | Bad Packets Report","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.debian.org/security/2018/dsa-4156","name":"DSA-4156","refsource":"DEBIAN","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-4156-1 drupal7","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/a2u/CVE-2018-7600","name":"https://github.com/a2u/CVE-2018-7600","refsource":"MISC","tags":["Third Party Advisory"],"title":"GitHub - a2u/CVE-2018-7600: ????Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.drupal.org/sa-core-2018-002","name":"https://www.drupal.org/sa-core-2018-002","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002 | Drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"403"},{"url":"https://greysec.net/showthread.php?tid=2912&pid=10561","name":"https://greysec.net/showthread.php?tid=2912&pid=10561","refsource":"MISC","tags":["Issue Tracking","Third Party Advisory"],"title":"Any Exploit Code For \"CVE-2018-7600\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2018/03/msg00028.html","name":"[debian-lts-announce] 20180328 [SECURITY] [DLA 1325-1] drupal7 security update","refsource":"MLIST","tags":["Third Party Advisory"],"title":"[SECURITY] [DLA 1325-1] drupal7 security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://twitter.com/RicterZ/status/984495201354854401","name":"https://twitter.com/RicterZ/status/984495201354854401","refsource":"MISC","tags":["Third Party Advisory"],"title":"JavaScript is not available.","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/103534","name":"103534","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Drupal Core CVE-2018-7600 Multiple Remote Code Execution Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.exploit-db.com/exploits/44449/","name":"44449","refsource":"EXPLOIT-DB","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/g0rx/CVE-2018-7600-Drupal-RCE","name":"https://github.com/g0rx/CVE-2018-7600-Drupal-RCE","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"GitHub - g0rx/CVE-2018-7600-Drupal-RCE: CVE-2018-7600 Drupal RCE","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714","name":"https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714","refsource":"MISC","tags":["Third Party Advisory"],"title":"Remote Code Execution with Drupal core (SA-CORE-2018–002)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://groups.drupal.org/security/faq-2018-002","name":"https://groups.drupal.org/security/faq-2018-002","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"FAQ about SA-CORE-2018-002 | Drupal Groups","mime":"text/html","httpstatus":"200","archivestatus":"403"},{"url":"https://twitter.com/RicterZ/status/979567469726613504","name":"https://twitter.com/RicterZ/status/979567469726613504","refsource":"MISC","tags":["Third Party Advisory"],"title":"JavaScript is not available.","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.exploit-db.com/exploits/44448/","name":"44448","refsource":"EXPLOIT-DB","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC) - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know","name":"https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know","refsource":"MISC","tags":["Third Party Advisory"],"title":"Drupal Core Vulnerability CVE-2018-7600 Patch | Tenable®","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.synology.com/support/security/Synology_SA_18_17","name":"https://www.synology.com/support/security/Synology_SA_18_17","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"Synology Inc.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1040598","name":"1040598","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"Drupal Form API Flaw Lets Remote Users Execute Arbitrary Code on the Target System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://twitter.com/arancaytar/status/979090719003627521","name":"https://twitter.com/arancaytar/status/979090719003627521","refsource":"MISC","tags":["Third Party Advisory"],"title":"aran na Twitterze: \"The CVE is (obviously) coy about the actual exploit, but there's one subsystem that has been there for some ~12 years, relatively slow to change, and uses \"#\" as a control character in array keys.\n\nSo it's a reasonable guess that the Render API is involved.\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-7600","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-7600","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"7600","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"7600","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"7600","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"7600","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"7600","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"7600","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"7600","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"drupal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"7600","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"drupal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"7600","vulnerable":"1","versionEndIncluding":"7.57","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"drupal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2018","cve_id":"7600","cve":"CVE-2018-7600","vendorProject":"Drupal","product":"Drupal Core","vulnerabilityName":"Drupal Core Remote Code Execution Vulnerability","dateAdded":"2021-11-03","shortDescription":"Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-05-03","knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2018-7600","cwes":"CWE-20","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:16"},"epss":{"cve_year":"2018","cve_id":"7600","cve":"CVE-2018-7600","epss":"0.999930000","percentile":"0.999860000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:33"},"legacy_qids":[{"cve":"CVE-2018-7600","qid":"500870","title":"Alpine Linux Security Update for drupal7"},{"cve":"CVE-2018-7600","qid":"504694","title":"Alpine Linux Security Update for drupal7"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@drupal.org","ID":"CVE-2018-7600","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1","version":{"version_data":[{"version_value":"Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"remote code execution"}]}]},"references":{"reference_data":[{"name":"https://github.com/g0rx/CVE-2018-7600-Drupal-RCE","refsource":"MISC","url":"https://github.com/g0rx/CVE-2018-7600-Drupal-RCE"},{"name":"1040598","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1040598"},{"name":"https://twitter.com/arancaytar/status/979090719003627521","refsource":"MISC","url":"https://twitter.com/arancaytar/status/979090719003627521"},{"name":"https://twitter.com/RicterZ/status/979567469726613504","refsource":"MISC","url":"https://twitter.com/RicterZ/status/979567469726613504"},{"name":"https://www.drupal.org/sa-core-2018-002","refsource":"CONFIRM","url":"https://www.drupal.org/sa-core-2018-002"},{"name":"https://www.synology.com/support/security/Synology_SA_18_17","refsource":"CONFIRM","url":"https://www.synology.com/support/security/Synology_SA_18_17"},{"name":"https://github.com/a2u/CVE-2018-7600","refsource":"MISC","url":"https://github.com/a2u/CVE-2018-7600"},{"name":"44482","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/44482/"},{"name":"https://research.checkpoint.com/uncovering-drupalgeddon-2/","refsource":"MISC","url":"https://research.checkpoint.com/uncovering-drupalgeddon-2/"},{"name":"https://groups.drupal.org/security/faq-2018-002","refsource":"CONFIRM","url":"https://groups.drupal.org/security/faq-2018-002"},{"name":"DSA-4156","refsource":"DEBIAN","url":"https://www.debian.org/security/2018/dsa-4156"},{"name":"[debian-lts-announce] 20180328 [SECURITY] [DLA 1325-1] drupal7 security update","refsource":"MLIST","url":"https://lists.debian.org/debian-lts-announce/2018/03/msg00028.html"},{"name":"44448","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/44448/"},{"name":"103534","refsource":"BID","url":"http://www.securityfocus.com/bid/103534"},{"name":"https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/","refsource":"MISC","url":"https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/"},{"name":"https://greysec.net/showthread.php?tid=2912&pid=10561","refsource":"MISC","url":"https://greysec.net/showthread.php?tid=2912&pid=10561"},{"name":"https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714","refsource":"MISC","url":"https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714"},{"name":"https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know","refsource":"MISC","url":"https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know"},{"name":"https://twitter.com/RicterZ/status/984495201354854401","refsource":"MISC","url":"https://twitter.com/RicterZ/status/984495201354854401"},{"name":"44449","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/44449/"}]}},"nvd":{"publishedDate":"2018-03-29 07:29:00","lastModifiedDate":"2019-03-01 18:04:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*","versionEndIncluding":"7.57","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"8.3.9","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*","versionStartIncluding":"8.4.0","versionEndExcluding":"8.4.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*","versionStartIncluding":"8.5.0","versionEndExcluding":"8.5.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"7600","Ordinal":"123897","Title":"CVE-2018-7600","CVE":"CVE-2018-7600","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"7600","Ordinal":"1","NoteData":"Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"7600","Ordinal":"2","NoteData":"2018-03-29","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"7600","Ordinal":"3","NoteData":"2018-06-11","Type":"Other","Title":"Modified"}]}}}