Back

CVE-2018-7602

CRITICAL CISA KEV

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.

Published: Jul 19, 2018 Modified: Aug 13, 2026
NVD-CWE-noinfo CWE-94

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (6)

Vendor Product Version
drupal drupal * ≥ 7.0 < 7.59
drupal drupal * ≥ 8.4.0 < 8.4.8
drupal drupal * ≥ 8.5.0 < 8.5.3
debian debian_linux 7.0
debian debian_linux 8.0
debian debian_linux 9.0

GitHub Security Advisory GHSA-297x-j9pm-xjgg

Drupal Core Remote Code Execution Vulnerability

composer drupal/core >= 7.0, < 7.59 Fixed: 7.59
composer drupal/core >= 8.0, < 8.4.8 Fixed: 8.4.8
composer drupal/core >= 8.5, < 8.5.3 Fixed: 8.5.3
composer drupal/drupal >= 7.0, < 7.59 Fixed: 7.59
composer drupal/drupal >= 8.0, < 8.4.8 Fixed: 8.4.8
composer drupal/drupal >= 8.5, < 8.5.3 Fixed: 8.5.3

References (15)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 99.24%

Top 0% most likely to be exploited

Threat Score 99 / 100

CISA Known Exploited

Date Added: 2022-04-13
Due Date: 2022-05-04
Required Action:

Apply updates per vendor instructions.

Used in Ransomware Campaigns

Data Sources

NVD CISA KEV EPSS GitHub