« Back to list

CVE-2018-7600

Status: AnalyzedCritical (9.8)⚠ Active exploitation💥 Exploit

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

CISA KEV — actively exploited

💥 Public exploits

Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.

⚠️ GitHub proofs of concept are not verified: some are fake or contain malware. Never run them outside an isolated lab.

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

Drupal vulnerable a ejecución remota de código sin autenticación (AV:N, PR:N, UI:N). CVSS crítico (C:H, I:H, A:H) confirma impactos en ejecución, disponibilidad y confidencialidad.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2018-7600",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2018-7600",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "active"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-07T12:40:15.444546Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "mlhess@drupal.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1",
          "versions": [
            {
              "status": "affected",
              "version": "Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-03-29T07:29:00.260",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/103534",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "http://www.securitytracker.com/id/1040598",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://github.com/a2u/CVE-2018-7600",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://github.com/g0rx/CVE-2018-7600-Drupal-RCE",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://greysec.net/showthread.php?tid=2912&pid=10561",
      "tags": [
        "Broken Link",
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://groups.drupal.org/security/faq-2018-002",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2018/03/msg00028.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://research.checkpoint.com/uncovering-drupalgeddon-2/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://twitter.com/RicterZ/status/979567469726613504",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://twitter.com/RicterZ/status/984495201354854401",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://twitter.com/arancaytar/status/979090719003627521",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://www.debian.org/security/2018/dsa-4156",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://www.drupal.org/sa-core-2018-002",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/44448/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/44449/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/44482/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://www.synology.com/support/security/Synology_SA_18_17",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/103534",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1040598",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://blog.appsecco.com/remote-code-execution-with-drupal-core-sa-core-2018-002-95e6ecc0c714",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/a2u/CVE-2018-7600",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/g0rx/CVE-2018-7600-Drupal-RCE",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://greysec.net/showthread.php?tid=2912&pid=10561",
      "tags": [
        "Broken Link",
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://groups.drupal.org/security/faq-2018-002",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2018/03/msg00028.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://research.checkpoint.com/uncovering-drupalgeddon-2/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://twitter.com/RicterZ/status/979567469726613504",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://twitter.com/RicterZ/status/984495201354854401",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://twitter.com/arancaytar/status/979090719003627521",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.debian.org/security/2018/dsa-4156",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/sa-core-2018-002",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/44448/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/44449/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/44482/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.synology.com/support/security/Synology_SA_18_17",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.tenable.com/blog/critical-drupal-core-vulnerability-what-you-need-to-know",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-7600",
      "tags": [
        "US Government Resource"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations."
    },
    {
      "lang": "es",
      "value": "Drupal en versiones anteriores a la 7.58, 8.x anteriores a la 8.3.9, 8.4.x anteriores a la 8.4.6 y 8.5.x anteriores a la 8.5.1 permite que los atacantes remotos ejecuten código arbitrario debido a un problema que afecta a múltiples subsistemas con configuraciones de módulos por defecto o comunes."
    }
  ],
  "lastModified": "2026-06-17T02:03:25.850",
  "cisaActionDue": "2022-05-03",
  "cisaExploitAdd": "2021-11-03",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32918FBA-EEAE-4103-AD2A-0E1914790A2D",
              "versionEndIncluding": "7.57"
            },
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB9AA188-842A-4465-833B-066371D5611E",
              "versionEndExcluding": "8.3.9",
              "versionStartIncluding": "8.0.0"
            },
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C796B60-2568-4E1F-A4CC-710DF21924BD",
              "versionEndExcluding": "8.4.6",
              "versionStartIncluding": "8.4.0"
            },
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE407010-FFFB-454E-B14A-56AD24B2997C",
              "versionEndExcluding": "8.5.1",
              "versionStartIncluding": "8.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16F59A04-14CF-49E2-9973-645477EA09DA"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DEECE5FC-CACF-4496-A3E7-164736409252"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "mlhess@drupal.org",
  "cisaRequiredAction": "Apply updates per vendor instructions.",
  "cisaVulnerabilityName": "Drupal Core Remote Code Execution Vulnerability"
}