CVE-2018-7600 - MergeBase Vulnerability Database
Risk Score
High severity
Out of 10
Mar 29, 2018
Mar 1, 2019


Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
MergeBase Comment

The forms feature in Drupal allows you to inject properties through an unintentional effect of the "Renderable Arrays" feature.

A Malicious user can inject a payload into a vulnerable AJAX form which can achieve remote code execution if they can successfully POST to a vulnerable form endpoint. This exploit is very simple, and scriptable payloads are available on public exploit databases. If any of your public servers are vulnerable to this exploit, automated exploit systems will likely attempt to gain access.

For more information, see the following research.

Vulnerability Fixed in: 7.58, 8.3.9, 8.4.6, 8.5.1

Common Weakness Enumeration (CWE)

Discover More from MergeBase

Open Source Protection

Stay on top of the real risk of open source at any time.

Avoid false positives and get sophisticated upgrade guidance based on risk, compatibility and popularity.

More on Continuous Protection

Add RunTime Protection

Detect and defend against known-vulnerabilities at runtime. The only SCA to do so.

The quickest way to respond to an imminent threat like log4j with CVE-2021-44228.

More on Run-time Protection

Shift Left Now

CodeGreen is an early-warning defence for your in-house development and integrates directly into GitHub and BitBucket

More on BitBucket and Github apps