VDB

CVE-2018-7600

CVE-2018-7600 PUBLISHED KEV CVSS 9.800000190734863 CRITICAL

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

EPSS 99.99% · 100.0th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
99.99%
100.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSdrupal77.38-1, 7.41-1, 0
Ubuntu:Pro:14.04:LTSdrupal77.26-1, 0, 7.26-1ubuntu0.1

Timeline

  • CVE Published
  • Mar 30, 2018 VulnCheck XDB Entry
  • Mar 30, 2018 VulnCheck XDB Entry
  • Apr 12, 2018 VulnCheck XDB Entry
  • Apr 13, 2018 PoC Published
  • Apr 13, 2018 PoC Published
  • Apr 13, 2018 VulnCheck XDB Entry
  • Apr 14, 2018 VulnCheck XDB Entry
  • Apr 14, 2018 VulnCheck XDB Entry
  • Apr 15, 2018 VulnCheck XDB Entry
  • Apr 16, 2018 VulnCheck XDB Entry
  • Apr 17, 2018 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›