CVE-2019-6340

Confirmed PUBLISHED

Drupal core - Highly critical - Remote Code Execution

Drupal · Drupal Core
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.1 High EPSS 92.0%

At a Glance

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)

nuclei_scanner windows cisa metasploit php drupal
CVE Published
Feb 21, 2019
Exploitation Reported
Mar 25, 2022
CVSS
8.1 High
EPSS
92.0%
Remote No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Drupal
Drupal Core

8.5 to < 8.5.11

Affected
Drupal
Drupal Core

8.6 to < 8.6.10

Affected

CVE References

  • 46452 exploit-db.com · Exploit https://www.exploit-db.com/exploits/46452/
  • 46510 exploit-db.com · Exploit https://www.exploit-db.com/exploits/46510/
  • 46459 exploit-db.com · Exploit https://www.exploit-db.com/exploits/46459/
  • 107106 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/107106
  • synology.com/security/advisory/Synology_SA_19_09 synology.com · CVE Record https://www.synology.com/security/advisory/Synology_SA_19_09
Show 1 more reference

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.