← Back

CVE-2018-7600

Published: Mar 29, 2018Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

Affected (7)

1 product
Drupal
1 product
Debian Linux
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Drupal
Up to 7.57
From 8.0.0 to 8.3.9
From 8.4.0 to 8.4.6
From 8.5.0 to 8.5.1
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 7.0
Version 8.0
Version 9.0

References (41)

Source: mlhess@drupal.org
Broken LinkThird Party AdvisoryVDB Entry
Source: mlhess@drupal.org
Broken LinkThird Party AdvisoryVDB Entry
Source: mlhess@drupal.org
Third Party Advisory
Source: mlhess@drupal.org
PatchThird Party Advisory
Source: mlhess@drupal.org
Broken LinkIssue TrackingThird Party Advisory
Source: mlhess@drupal.org
Vendor Advisory
Source: mlhess@drupal.org
Third Party Advisory
Source: mlhess@drupal.org
ExploitThird Party Advisory
Source: mlhess@drupal.org
Broken LinkThird Party Advisory
Source: mlhess@drupal.org
Broken LinkThird Party Advisory
Source: mlhess@drupal.org
Third Party Advisory
Source: mlhess@drupal.org
Third Party Advisory
Source: mlhess@drupal.org
Vendor Advisory
Source: mlhess@drupal.org
ExploitThird Party AdvisoryVDB Entry
Source: mlhess@drupal.org
ExploitThird Party AdvisoryVDB Entry
Source: mlhess@drupal.org
ExploitThird Party AdvisoryVDB Entry
Source: mlhess@drupal.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.