VOOZH about

URL: https://nvd.nist.gov/vuln/detail/CVE-2018-7600

⇱ NVD - CVE-2018-7600


  1. Vulnerabilities

CVE-2018-7600 Detail

Description

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.


Metrics

 
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:

NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

URL Source(s) Tag(s)
http://www.securityfocus.com/bid/103534 CVE, Drupal.org Broken Link  Third Party Advisory  VDB Entry 
http://www.securitytracker.com/id/1040598 CVE, Drupal.org Broken Link  Third Party Advisory  VDB Entry 
https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/ CVE, Drupal.org Broken Link  Third Party Advisory 
https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714 CVE, Drupal.org Third Party Advisory 
https://github.com/a2u/CVE-2018-7600 CVE, Drupal.org Third Party Advisory 
https://github.com/g0rx/CVE-2018-7600-Drupal-RCE CVE, Drupal.org Patch  Third Party Advisory 
https://greysec.net/showthread.php?tid=2912&pid=10561 CVE, Drupal.org Broken Link  Issue Tracking  Third Party Advisory 
https://groups.drupal.org/security/faq-2018-002 CVE, Drupal.org Vendor Advisory 
https://lists.debian.org/debian-lts-announce/2018/03/msg00028.html CVE, Drupal.org Third Party Advisory 
https://research.checkpoint.com/uncovering-drupalgeddon-2/ CVE, Drupal.org Exploit  Third Party Advisory 
https://twitter.com/RicterZ/status/979567469726613504 CVE, Drupal.org Broken Link  Third Party Advisory 
https://twitter.com/RicterZ/status/984495201354854401 CVE, Drupal.org Broken Link  Third Party Advisory 
https://twitter.com/arancaytar/status/979090719003627521 CVE, Drupal.org Third Party Advisory 
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-7600 CISA-ADP US Government Resource 
https://www.debian.org/security/2018/dsa-4156 CVE, Drupal.org Third Party Advisory 
https://www.drupal.org/sa-core-2018-002 CVE, Drupal.org Vendor Advisory 
https://www.exploit-db.com/exploits/44448/ CVE, Drupal.org Exploit  Third Party Advisory  VDB Entry 
https://www.exploit-db.com/exploits/44449/ CVE, Drupal.org Exploit  Third Party Advisory  VDB Entry 
https://www.exploit-db.com/exploits/44482/ CVE, Drupal.org Exploit  Third Party Advisory  VDB Entry 
https://www.synology.com/support/security/Synology_SA_18_17 CVE, Drupal.org Third Party Advisory 
https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know CVE, Drupal.org Third Party Advisory 

This CVE is in CISA's Known Exploited Vulnerabilities Catalog

Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.

Vulnerability Name Date Added Due Date Required Action
Drupal Core Remote Code Execution Vulnerability 11/03/2021 05/03/2022 Apply updates per vendor instructions.

Weakness Enumeration

CWE-ID CWE Name Source
CWE-20 Improper Input Validation πŸ‘ cwe source acceptance level
NIST  
CISA-ADP  

Known Affected Software Configurations Switch to CPE 2.2

CPEs loading, please wait.

Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.

Change History

22 change records found show changes

CVE Modified by CISA-ADP 6/16/2026 10:03:25 PM

Action Type Old Value New Value
Added SSVC
{"timestamp":"2025-02-07T12:40:15.444546Z","id":"CVE-2018-7600","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}


CVE Modified by Drupal.org 6/16/2026 10:03:25 PM

Action Type Old Value New Value
Added Affected
[{"vendor":"n/a","product":"Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1","versions":[{"version":"Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1","status":"affected"}]}]


Modified Analysis by NIST 10/31/2025 6:05:42 PM

Action Type Old Value New Value
Changed Reference Type
CVE: https://twitter.com/arancaytar/status/979090719003627521 Types: Broken Link, Third Party Advisory


CVE: https://twitter.com/arancaytar/status/979090719003627521 Types: Third Party Advisory


Changed Reference Type
Drupal.org: https://twitter.com/arancaytar/status/979090719003627521 Types: Broken Link, Third Party Advisory


Drupal.org: https://twitter.com/arancaytar/status/979090719003627521 Types: Third Party Advisory


Added Reference Type
CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-7600 Types: US Government Resource


CVE Modified by CISA-ADP 10/21/2025 8:16:26 PM

Action Type Old Value New Value
Added Reference
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-7600


CVE Modified by CISA-ADP 10/21/2025 4:17:16 PM

Action Type Old Value New Value
Removed Reference
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-7600


CVE Modified by CISA-ADP 10/21/2025 3:17:33 PM

Action Type Old Value New Value
Added Reference
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-7600


Modified Analysis by NIST 3/14/2025 4:50:41 PM

Action Type Old Value New Value
Changed Reference Type
CVE: http://www.securityfocus.com/bid/103534 Types: Third Party Advisory, VDB Entry


CVE: http://www.securityfocus.com/bid/103534 Types: Broken Link, Third Party Advisory, VDB Entry


Changed Reference Type
CVE: http://www.securitytracker.com/id/1040598 Types: Third Party Advisory, VDB Entry


CVE: http://www.securitytracker.com/id/1040598 Types: Broken Link, Third Party Advisory, VDB Entry


Changed Reference Type
CVE: https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/ Types: Third Party Advisory


CVE: https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/ Types: Broken Link, Third Party Advisory


Changed Reference Type
CVE: https://greysec.net/showthread.php?tid=2912&pid=10561 Types: Issue Tracking, Third Party Advisory


CVE: https://greysec.net/showthread.php?tid=2912&pid=10561 Types: Broken Link, Issue Tracking, Third Party Advisory


Changed Reference Type
CVE: https://twitter.com/RicterZ/status/979567469726613504 Types: Third Party Advisory


CVE: https://twitter.com/RicterZ/status/979567469726613504 Types: Broken Link, Third Party Advisory


Changed Reference Type
CVE: https://twitter.com/RicterZ/status/984495201354854401 Types: Third Party Advisory


CVE: https://twitter.com/RicterZ/status/984495201354854401 Types: Broken Link, Third Party Advisory


Changed Reference Type
CVE: https://twitter.com/arancaytar/status/979090719003627521 Types: Third Party Advisory


CVE: https://twitter.com/arancaytar/status/979090719003627521 Types: Broken Link, Third Party Advisory


Changed Reference Type
Drupal.org: http://www.securityfocus.com/bid/103534 Types: Third Party Advisory, VDB Entry


Drupal.org: http://www.securityfocus.com/bid/103534 Types: Broken Link, Third Party Advisory, VDB Entry


Changed Reference Type
Drupal.org: http://www.securitytracker.com/id/1040598 Types: Third Party Advisory, VDB Entry


Drupal.org: http://www.securitytracker.com/id/1040598 Types: Broken Link, Third Party Advisory, VDB Entry


Changed Reference Type
Drupal.org: https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/ Types: Third Party Advisory


Drupal.org: https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/ Types: Broken Link, Third Party Advisory


Changed Reference Type
Drupal.org: https://greysec.net/showthread.php?tid=2912&pid=10561 Types: Issue Tracking, Third Party Advisory


Drupal.org: https://greysec.net/showthread.php?tid=2912&pid=10561 Types: Broken Link, Issue Tracking, Third Party Advisory


Changed Reference Type
Drupal.org: https://twitter.com/RicterZ/status/979567469726613504 Types: Third Party Advisory


Drupal.org: https://twitter.com/RicterZ/status/979567469726613504 Types: Broken Link, Third Party Advisory


Changed Reference Type
Drupal.org: https://twitter.com/RicterZ/status/984495201354854401 Types: Third Party Advisory


Drupal.org: https://twitter.com/RicterZ/status/984495201354854401 Types: Broken Link, Third Party Advisory


Changed Reference Type
Drupal.org: https://twitter.com/arancaytar/status/979090719003627521 Types: Third Party Advisory


Drupal.org: https://twitter.com/arancaytar/status/979090719003627521 Types: Broken Link, Third Party Advisory


CVE Modified by CISA-ADP 2/07/2025 8:15:24 AM

Action Type Old Value New Value
Added CVSS V3.1
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H


Added CWE
CWE-20


Modified Analysis by NIST 1/27/2025 4:25:54 PM

Action Type Old Value New Value
Added CVSS V3.1
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H


Removed CVSS V3
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H


CVE Modified by CVE 11/20/2024 11:12:25 PM

Action Type Old Value New Value
Added Reference
http://www.securityfocus.com/bid/103534


Added Reference
http://www.securitytracker.com/id/1040598


Added Reference
https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/


Added Reference
https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714


Added Reference
https://github.com/a2u/CVE-2018-7600


Added Reference
https://github.com/g0rx/CVE-2018-7600-Drupal-RCE


Added Reference
https://greysec.net/showthread.php?tid=2912&pid=10561


Added Reference
https://groups.drupal.org/security/faq-2018-002


Added Reference
https://lists.debian.org/debian-lts-announce/2018/03/msg00028.html


Added Reference
https://research.checkpoint.com/uncovering-drupalgeddon-2/


Added Reference
https://twitter.com/RicterZ/status/979567469726613504


Added Reference
https://twitter.com/RicterZ/status/984495201354854401


Added Reference
https://twitter.com/arancaytar/status/979090719003627521


Added Reference
https://www.debian.org/security/2018/dsa-4156


Added Reference
https://www.drupal.org/sa-core-2018-002


Added Reference
https://www.exploit-db.com/exploits/44448/


Added Reference
https://www.exploit-db.com/exploits/44449/


Added Reference
https://www.exploit-db.com/exploits/44482/


Added Reference
https://www.synology.com/support/security/Synology_SA_18_17


Added Reference
https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know


CVE Modified by Drupal.org 5/14/2024 1:26:24 AM

Action Type Old Value New Value

Modified Analysis by NIST 3/01/2019 1:04:28 PM

Action Type Old Value New Value
Changed Reference Type
https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/ No Types Assigned


https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/ Third Party Advisory


Changed Reference Type
https://www.exploit-db.com/exploits/44449/ Third Party Advisory, VDB Entry


https://www.exploit-db.com/exploits/44449/ Exploit, Third Party Advisory, VDB Entry


Changed Reference Type
https://www.exploit-db.com/exploits/44482/ Third Party Advisory, VDB Entry


https://www.exploit-db.com/exploits/44482/ Exploit, Third Party Advisory, VDB Entry


CVE Modified by Drupal.org 6/11/2018 9:29:02 PM

Action Type Old Value New Value
Added Reference
https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/ [No Types Assigned]


Initial Analysis by NIST 4/24/2018 8:47:49 AM

Action Type Old Value New Value
Added CVSS V3
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H


Added CVSS V2
(AV:N/AC:L/Au:N/C:P/I:P/A:P)


Added CWE
CWE-20


Added CPE Configuration
OR
 *cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* versions up to (including) 7.57
 *cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* versions from (including) 8.0.0 up to (excluding) 8.3.9
 *cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* versions from (including) 8.4.0 up to (excluding) 8.4.6
 *cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* versions from (including) 8.5.0 up to (excluding) 8.5.1


Added CPE Configuration
OR
 *cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
 *cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
 *cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*


Changed Reference Type
http://www.securityfocus.com/bid/103534 No Types Assigned


http://www.securityfocus.com/bid/103534 Third Party Advisory, VDB Entry


Changed Reference Type
http://www.securitytracker.com/id/1040598 No Types Assigned


http://www.securitytracker.com/id/1040598 Third Party Advisory, VDB Entry


Changed Reference Type
https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714 No Types Assigned


https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714 Third Party Advisory


Changed Reference Type
https://github.com/a2u/CVE-2018-7600 No Types Assigned


https://github.com/a2u/CVE-2018-7600 Third Party Advisory


Changed Reference Type
https://github.com/g0rx/CVE-2018-7600-Drupal-RCE No Types Assigned


https://github.com/g0rx/CVE-2018-7600-Drupal-RCE Patch, Third Party Advisory


Changed Reference Type
https://greysec.net/showthread.php?tid=2912&pid=10561 No Types Assigned


https://greysec.net/showthread.php?tid=2912&pid=10561 Issue Tracking, Third Party Advisory


Changed Reference Type
https://groups.drupal.org/security/faq-2018-002 No Types Assigned


https://groups.drupal.org/security/faq-2018-002 Vendor Advisory


Changed Reference Type
https://lists.debian.org/debian-lts-announce/2018/03/msg00028.html No Types Assigned


https://lists.debian.org/debian-lts-announce/2018/03/msg00028.html Third Party Advisory


Changed Reference Type
https://research.checkpoint.com/uncovering-drupalgeddon-2/ No Types Assigned


https://research.checkpoint.com/uncovering-drupalgeddon-2/ Exploit, Third Party Advisory


Changed Reference Type
https://twitter.com/RicterZ/status/979567469726613504 No Types Assigned


https://twitter.com/RicterZ/status/979567469726613504 Third Party Advisory


Changed Reference Type
https://twitter.com/RicterZ/status/984495201354854401 No Types Assigned


https://twitter.com/RicterZ/status/984495201354854401 Third Party Advisory


Changed Reference Type
https://twitter.com/arancaytar/status/979090719003627521 No Types Assigned


https://twitter.com/arancaytar/status/979090719003627521 Third Party Advisory


Changed Reference Type
https://www.debian.org/security/2018/dsa-4156 No Types Assigned


https://www.debian.org/security/2018/dsa-4156 Third Party Advisory


Changed Reference Type
https://www.drupal.org/sa-core-2018-002 No Types Assigned


https://www.drupal.org/sa-core-2018-002 Vendor Advisory


Changed Reference Type
https://www.exploit-db.com/exploits/44448/ No Types Assigned


https://www.exploit-db.com/exploits/44448/ Exploit, Third Party Advisory, VDB Entry


Changed Reference Type
https://www.exploit-db.com/exploits/44449/ No Types Assigned


https://www.exploit-db.com/exploits/44449/ Third Party Advisory, VDB Entry


Changed Reference Type
https://www.exploit-db.com/exploits/44482/ No Types Assigned


https://www.exploit-db.com/exploits/44482/ Third Party Advisory, VDB Entry


Changed Reference Type
https://www.synology.com/support/security/Synology_SA_18_17 No Types Assigned


https://www.synology.com/support/security/Synology_SA_18_17 Third Party Advisory


Changed Reference Type
https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know No Types Assigned


https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know Third Party Advisory


CVE Modified by Drupal.org 4/19/2018 9:29:32 PM

Action Type Old Value New Value
Added Reference
https://www.exploit-db.com/exploits/44482/ [No Types Assigned]


CVE Modified by Drupal.org 4/16/2018 5:58:11 AM

Action Type Old Value New Value
Added Reference
https://www.exploit-db.com/exploits/44448/ [No Types Assigned]


Added Reference
https://www.exploit-db.com/exploits/44449/ [No Types Assigned]


CVE Modified by Drupal.org 4/12/2018 9:29:13 PM

Action Type Old Value New Value
Added Reference
https://research.checkpoint.com/uncovering-drupalgeddon-2/ [No Types Assigned]


Added Reference
https://twitter.com/RicterZ/status/984495201354854401 [No Types Assigned]


CVE Modified by Drupal.org 4/02/2018 9:29:01 PM

Action Type Old Value New Value
Added Reference
https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714 [No Types Assigned]


CVE Modified by Drupal.org 4/01/2018 9:29:00 PM

Action Type Old Value New Value
Added Reference
https://twitter.com/arancaytar/status/979090719003627521 [No Types Assigned]


CVE Modified by Drupal.org 3/31/2018 9:29:02 PM

Action Type Old Value New Value
Added Reference
https://github.com/g0rx/CVE-2018-7600-Drupal-RCE [No Types Assigned]


Added Reference
https://greysec.net/showthread.php?tid=2912&pid=10561 [No Types Assigned]


Added Reference
https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know [No Types Assigned]


CVE Modified by Drupal.org 3/30/2018 9:29:03 PM

Action Type Old Value New Value
Added Reference
https://github.com/a2u/CVE-2018-7600 [No Types Assigned]


Added Reference
https://twitter.com/RicterZ/status/979567469726613504 [No Types Assigned]


Added Reference
https://www.debian.org/security/2018/dsa-4156 [No Types Assigned]


Added Reference
https://www.synology.com/support/security/Synology_SA_18_17 [No Types Assigned]


CVE Modified by Drupal.org 3/29/2018 9:29:03 PM

Action Type Old Value New Value
Added Reference
http://www.securityfocus.com/bid/103534 [No Types Assigned]


Added Reference
http://www.securitytracker.com/id/1040598 [No Types Assigned]


Added Reference
https://lists.debian.org/debian-lts-announce/2018/03/msg00028.html [No Types Assigned]


Quick Info

CVE Dictionary Entry:
CVE-2018-7600
NVD Published Date:
03/29/2018
NVD Last Modified:
06/16/2026
Source:
Drupal.org