Code injection in Drupal - CVE-2018-7602
Published: April 25, 2018 / Updated: June 17, 2021
Vulnerability identifier: #VU12182
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7602
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable website.
The vulnerability exists due to improper input validation when processing HTTP requests. A remote unauthenticated attacker can send a specially crafted HTTP request to vulnerable website and compromise it.
Successful exploitation of the vulnerability may allow an attacker to gain full access to vulnerable website.
Note: the vendor updated the original advisory stating that this vulnerability is being exploited in the wild.
The vulnerability exists due to improper input validation when processing HTTP requests. A remote unauthenticated attacker can send a specially crafted HTTP request to vulnerable website and compromise it.
Successful exploitation of the vulnerability may allow an attacker to gain full access to vulnerable website.
Note: the vendor updated the original advisory stating that this vulnerability is being exploited in the wild.
Affected software
Drupal
Arch Linux
Debian Linux
Fedora
drupal7 (Debian package)
drupal7 (Alpine package)
drupal7
drupal8
Arch Linux
Debian Linux
Fedora
drupal7 (Debian package)
drupal7 (Alpine package)
drupal7
drupal8
How to mitigate CVE-2018-7602
Update to version 7.59, 8.4.8 or 8.5.3.
drupal7 (Debian package) - update to 7.52-2+deb9u5
drupal7 (Alpine package) - update to 7.59-r0
drupal7 - addressed in versions 7.59-1.el6, 7.59-1.el7, 7.59-1.fc26, 7.59-1.fc27, 7.59-1.fc28
drupal8 - addressed in versions 8.4.8-1.fc27, 8.4.8-1.fc28
drupal7 (Alpine package) - update to 7.59-r0
drupal7 - addressed in versions 7.59-1.el6, 7.59-1.el7, 7.59-1.fc26, 7.59-1.fc27, 7.59-1.fc28
drupal8 - addressed in versions 8.4.8-1.fc27, 8.4.8-1.fc28
Links to Public Exploits and PoC-codes
- Exploit #6214 - Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit) (June 17, 2021)
- Exploit #6215 - Drupal < 7.58 - 'drupalgeddon3' (Authenticated) Remote Code Execution (PoC) (June 17, 2021)
- Exploit #2305 - exphub (Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340) (April 7, 2020)
- Exploit #2293 - Exploits (Containing Self Made Perl Reproducers / PoC Codes) (April 7, 2020)
- Exploit #2032 - Drupalgeddon-Mass-Exploiter (CVE-2018-7600 and CVE-2018-7602 Mass Exploiter) (March 18, 2020)
- Exploit #1929 - Drupalgedon3 (POC to test/exploit drupal vulnerability SA-CORE-2018-004 / CVE-2018-7602) (March 18, 2020)
- Exploit #1930 - CVE-2018-7600 (Exploit for Drupal 7 <= 7.57 CVE-2018-7600) (March 18, 2020)
External References
Related Security Bulletins
- Remote code execution in Drupal
- Debian update for drupal7
- Arch Linux update for drupal
- Debian update for drupal7
- Code injection in drupal7 (Alpine package)
- Fedora EPEL 7 update for drupal7
- Fedora 26 update for drupal7
- Fedora EPEL 6 update for drupal7
- Fedora 28 update for drupal7
- Fedora 27 update for drupal7
- Fedora 28 update for drupal8
- Fedora 27 update for drupal8