← back
CVE-2018-7600

CVE-2018-7600

CVSS 9.8 CRITICALEPSS 100.0%● KEVCWE-20
In short

Drupal versions before 7.58, 8.3.9, 8.4.6, and 8.5.1 contain a critical vulnerability that allows attackers to run malicious code on affected websites. This happens because multiple core systems don't properly validate certain inputs when using default or common configurations.

Technical detail

A remote attacker can execute arbitrary code in vulnerable Drupal installations through improper input validation in multiple subsystems. The vulnerability affects default and commonly-used module configurations without requiring authentication. Successful exploitation leads to complete system compromise.

Summary generated and translated by AI from the official description.
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
public PoCs found56
githubgithub.com/dreadlocked/Drupalgeddon2599githubgithub.com/a2u/CVE-2018-7600354githubgithub.com/pimps/CVE-2018-7600141githubgithub.com/g0rx/CVE-2018-7600-Drupal-RCE114githubgithub.com/firefart/CVE-2018-760072githubgithub.com/lorddemon/drupalgeddon211githubgithub.com/r3dxpl0it/CVE-2018-76009githubgithub.com/zhzyker/CVE-2018-7600-Drupal-POC-EXP8githubgithub.com/rabbitmask/CVE-2018-7600-Drupal78githubgithub.com/dr-iman/CVE-2018-7600-Drupal-0day-RCE7githubgithub.com/thehappydinoa/CVE-2018-76007githubgithub.com/jirojo2/drupalgeddon25githubgithub.com/shellord/CVE-2018-7600-Drupal-RCE4githubgithub.com/sl4cky/CVE-2018-76004githubgithub.com/ludy-dev/drupal8-REST-RCE4githubgithub.com/dwisiswant0/CVE-2018-76004githubgithub.com/sl4cky/CVE-2018-7600-Masschecker3githubgithub.com/knqyf263/CVE-2018-76003githubgithub.com/Hestat/drupal-check2githubgithub.com/ynsmroztas/drupalhunter1githubgithub.com/Damian972/drupalgeddon-21githubgithub.com/drugeddon/drupal-exploit1githubgithub.com/shellord/Drupalgeddon-Mass-Exploiter1githubgithub.com/0xAJ2K/CVE-2018-76001githubgithub.com/muhammedkayag/CVE-2018-76001githubgithub.com/4l13n-DN/POC-CVE-2018-76001githubgithub.com/Meraj1312/cve-2018-7600-drupalgeddon2-lab1githubgithub.com/soch4n/CVE-2018-76000githubgithub.com/erman-bolukbasi/web-penetration-drupal0githubgithub.com/happynote3966/CVE-2018-76000githubgithub.com/cved-sources/cve-2018-76000githubgithub.com/madneal/codeql-scanner0githubgithub.com/MoriartyPuth-Labs/DC1-Lab0githubgithub.com/Dungsocool/CVE-2018-76000githubgithub.com/ruthvikvegunta/Drupalgeddon20githubgithub.com/nayem-m/drupalgeddon2-cli0githubgithub.com/rafaelcaria/drupalgeddon2-CVE-2018-76000githubgithub.com/vphnguyen/ANM_CVE-2018-76000githubgithub.com/anldori/CVE-2018-76000githubgithub.com/r0lh/CVE-2018-76000githubgithub.com/raytran54/CVE-2018-76000githubgithub.com/tpdlshdmlrkfmcla/CVE-2018-7600.0githubgithub.com/Dowonkwon/drupal-cve-2018-7600-poc0githubgithub.com/M-Abid34/CVE-2018-76000githubgithub.com/rajaabdullahnasir/CVE-2018-7600-Remote-Code-Execution0githubgithub.com/xxxTectationxxx/CVE-2018-76000githubgithub.com/SyedGhufranRaza/CVE-2018-7600-Remote-Code-Execution0githubgithub.com/nika0x38/CVE-2018-76000githubgithub.com/tea-celikik/Drupal-Exploit-Lab0githubgithub.com/bixiPRO/Drupalgeddon2-CVE-2018-76000cve_referencewww.exploit-db.com/exploits/44448/unverifiedexploitdbwww.exploit-db.com/exploits/44482unverifiedcve_referencewww.exploit-db.com/exploits/44449/unverifiedexploitdbwww.exploit-db.com/exploits/44449unverifiedcve_referencewww.exploit-db.com/exploits/44482/unverifiedexploitdbwww.exploit-db.com/exploits/44448unverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →