OS command injection in Drupal - #VU15405

 

OS command injection in Drupal - #VU15405

Published: October 18, 2018


Vulnerability identifier: #VU15405
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to compromise vulnerable system.

The vulnerability exists due to insufficient sanitization of the user-supplied input when sending email messages via DefaultMailSystem::mail() function. A remote attacker can inject and execute arbitrary OS commands on the vulnerable system with privileges of the web server.

Affected software

Drupal
drupal7 (Debian package)

Remediation

Install updates from vendor's website.

Drupal - addressed in versions 7.60, 8.5.8, 8.6.2
drupal7 (Debian package) - update to 7.52-2+deb9u5

External References

Related Security Bulletins