CVE-2019-6340
Drupal Core: Remote Code Execution
As of , CVE-2019-6340 in Drupal Core is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 25 March 2022
- US federal deadline
- 15 April 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.92Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- 0.95 on 25 March 2022EPSS on the day CISA listed it.
- Public exploit
- 1 Metasploit module and 3 Exploit-DB entries (1 verified)
- Fix
- No vendor link in CISA's entry
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
CISA's description
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)
The CVE record's description, from drupal
- CVE published
- 21 February 2019
- Assigned by
- drupal
- CVSS
- 8.1 High (CVSS 3.1, from CISA-ADP)
- CWE-502
- Deserialization of Untrusted Data
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- Exploit-DB published an exploit (EDB-ID 46452).
- Exploit-DB published an exploit (EDB-ID 46459).
- Exploit-DB published an exploit (EDB-ID 46510).
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: Drupal RESTful Web Services unserialize() RCEexploit module, rank normal
- Exploit-DB: Drupal < 8.5.11 / < 8.6.10 - RESTful Web Services unserialize() Remote Command Execution (Metasploit)EDB-ID 46510, verified by Exploit-DB, 7 March 2019
- Exploit-DB: Drupal < 8.6.9 - REST Module Remote Code ExecutionEDB-ID 46459, 25 February 2019
- Exploit-DB: Drupal < 8.6.10 / < 8.5.11 - REST Module Remote Code ExecutionEDB-ID 46452, 23 February 2019
Core: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-9082SQL Injection | Drupal Core | Patch this weekMetasploit module | 0.16 | ||
| CVE-2018-7602Remote Code Execution | Drupal Core | Patch this weekRansomware use; EPSS 0.99; verified Exploit-DB entry | 0.99 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org