#VU6110 PHP code injection in Drupal - CVE-2017-6381
Published: March 17, 2017 / Updated: March 24, 2017
Drupal
Drupal
Description
The vulnerability allows a remote attacker to execute arbitrary PHP code on the target system.
The vulnerability exists due to usage of a 3rd party development library in Drupal before 8.2.2. A remote attacker send a specially crafted request to /vendor/phpunit URL and execute arbitrary PHP code on the server.