CVE record
CVE-2018-7602
Drupal Core Remote Code Execution Vulnerability
A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
CVE evidence
Known exploitation
Listed in CISA KEV
Absence from the fetched catalog does not establish that exploitation has not occurred.
Severity
critical
CVSS 9.8 ยท CVSS_V3
Affected packages
2
Supported package records returned by OSV. Vendor and product names are not used to infer matches.
CISA Known Exploited Vulnerabilities
Catalog record
- Vendor / project
- Drupal
- Product
- Core
- Date added
- Apr 13, 2022
- CISA federal remediation due date
- May 4, 2022
- Required action
- Apply updates per vendor instructions.
- Known ransomware campaign use
- Known
- CWE
- Not supplied
OSV package mapping
Affected open-source packages
| Package | Ecosystem | Fixed versions |
|---|---|---|
| drupal/core | composer | 8.4.8, 8.5.3, 7.59 |
| drupal/drupal | composer | 7.59, 8.4.8, 8.5.3 |