← back
CVE-2019-6340highunder attackCWE-502

Drupal core - Highly critical - Remote Code Execution

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 8.1epss 92%
from disclosure to weapon1 days
Published on NVDFeb 21
1st PoC+1d
metasploitFeb 20
CISA KEV+1128d
exploitation probability
92%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
23 public exploit(s)
Action required by CISAfederal deadline: 2022-04-15

Apply updates per vendor instructions.

Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Drupal · Drupal Core
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.