CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2018-7602

KEV · ransomware Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
KEV
Listed
ransomware
Class
oss containerizable
NVD-CWE-noinfo, CWE-94

Description

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.

Affected packages

Packagist drupal/core 7.0 → 7.59
Packagist drupal/core 8.0 → 8.4.8
Packagist drupal/core 8.0.0 → 8.4.8
Packagist drupal/core 8.5 → 8.5.3
Packagist drupal/core 8.5.0 → 8.5.3
Packagist drupal/drupal 7.0 → 7.59
Packagist drupal/drupal 8.0 → 8.4.8
Packagist drupal/drupal 8.5 → 8.5.3

References

Status: profiled · ingested 2026-08-13T06:00:50.000Z