CVE-2018-7600: Drupalgeddon2
A remote code execution vulnerability in Drupal core caused by insufficient sanitization of input reaching Drupal's Form API AJAX handling. An unauthenticated attacker can inject a renderable array into a request and have Drupal execute arbitrary PHP, without needing an account on the target site.
View the authoritative record on NVD ↗Affected software
- Drupal 7.x before 7.58
- Drupal 8.x before 8.3.9
- Drupal 8.4.x before 8.4.6
- Drupal 8.5.x before 8.5.1
How it's exploited
Send a crafted POST request with array-based parameter keys to a Drupal form endpoint (such as user/register); Drupal's rendering pipeline interprets the injected keys as a renderable array, allowing arbitrary PHP execution.
Severity
CVE-2018-7600 carries a CVSS 3.1 base score of 9.8, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2018-7600 is categorized under CWE-20, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Upgrade to Drupal 7.58, 8.3.9, 8.4.6, or 8.5.1 or later, per Drupal security advisory SA-CORE-2018-002.
Frequently asked questions
What is CVE-2018-7600?
A remote code execution vulnerability in Drupal core caused by insufficient sanitization of input reaching Drupal's Form API AJAX handling. An unauthenticated attacker can inject a renderable array into a request and have Drupal execute arbitrary PHP, without needing an account on the target site.
How severe is CVE-2018-7600?
CVE-2018-7600 has a CVSS 3.1 base score of 9.8 out of 10, rated Critical.
What software is affected by CVE-2018-7600?
CVE-2018-7600 affects Drupal 7.x before 7.58; Drupal 8.x before 8.3.9; Drupal 8.4.x before 8.4.6; Drupal 8.5.x before 8.5.1.
How do you fix CVE-2018-7600?
Upgrade to Drupal 7.58, 8.3.9, 8.4.6, or 8.5.1 or later, per Drupal security advisory SA-CORE-2018-002.
Where is the authoritative record for CVE-2018-7600?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2018-7600 at https://nvd.nist.gov/vuln/detail/CVE-2018-7600, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest