CVE-2019-6340 KEV EXPLOIT
Patch first
On CISA KEV — known exploited in the wild, due 2022-04-15.
Description
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)
Scoring
| CVSS | 8.1 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 92.02% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | yes — remediate by 2022-04-15 |
| Public exploit | yes |
| Published | 2019-02-21 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Drupal Core Remote Code Execution Vulnerability |
|---|---|
| Added | 2022-03-25 |
| Due | 2022-04-15 |
| Vendor / product | Drupal / Core |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| drupal | drupal |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Drupal < 8.5.11 / < 8.6.10 - RESTful Web Services unserialize() Remote Command Execution (Metasploit) | 2019-03-07 |
| exploit-db | Drupal < 8.6.9 - REST Module Remote Code Execution | 2019-02-25 |
| exploit-db | Drupal < 8.6.10 / < 8.5.11 - REST Module Remote Code Execution | 2019-02-23 |
References
- http://www.securityfocus.com/bid/107106
- https://www.drupal.org/sa-core-2019-003
- https://www.exploit-db.com/exploits/46452/
- https://www.exploit-db.com/exploits/46459/
- https://www.exploit-db.com/exploits/46510/
- https://www.synology.com/security/advisory/Synology_SA_19_09
- http://www.securityfocus.com/bid/107106
- https://www.drupal.org/sa-core-2019-003
- https://www.exploit-db.com/exploits/46452/
- https://www.exploit-db.com/exploits/46459/
- https://www.exploit-db.com/exploits/46510/
- https://www.synology.com/security/advisory/Synology_SA_19_09
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-6340
→ the Explorer · watch your stack · NVD