#VU17234 Input validation error in Drupal - CVE-2019-6339
Published: January 28, 2019
Drupal
Drupal
Description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) due to insufficient validation of user-supplied input. A remote attacker can submit specially crafted input and execute arbitrary PHP code.