OS command injection in Drupal - #VU15405
Published: October 18, 2018
Vulnerability identifier: #VU15405
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to compromise vulnerable system.
The vulnerability exists due to insufficient sanitization of the user-supplied input when sending email messages via DefaultMailSystem::mail() function. A remote attacker can inject and execute arbitrary OS commands on the vulnerable system with privileges of the web server.
Affected software
Drupal
drupal7 (Debian package)
drupal7 (Debian package)
Remediation
Install updates from vendor's website.
Drupal - addressed in versions 7.60, 8.5.8, 8.6.2
drupal7 (Debian package) - update to 7.52-2+deb9u5
drupal7 (Debian package) - update to 7.52-2+deb9u5