KEVIntel
8.1
CVSS
High

CVE-2019-6340

PUBLISHED

Drupal core - Highly critical - Remote Code Execution

Exploited in the wild Remote No user interaction
Vendor
Drupal
Product
Drupal Core
Published
Feb 21, 2019
EPSS

Description

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)

drupal php windows cisa nuclei_scanner metasploit

CVSS scores

CVSS v3.1 8.1 High

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 6.8

AV:N/AC:M/Au:N/C:P/I:P/A:P

Exploitation status

Exploited in the wild

Recorded 2022-03-25 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Mar 25, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

drupal_restws_unserialize

metasploit · Created Unknown

Metasploit module for CVE-2019-6340

nobodyatall648/CVE-2019-6340

github · Created 2021-05-01 15:00:34 UTC · 0 stars

Drupal Drupal 8.6.x RCE Exploit

jas502n/CVE-2019-6340

github · Created 2019-05-27 19:06:14 UTC · 70 stars

Drupal8's REST RCE, SA-CORE-2019-003, CVE-2019-6340

oways/CVE-2019-6340

github · Created 2019-02-25 07:47:16 UTC · 12 stars

CVE-2019-6340 POC Drupal rce

DevDungeon/CVE-2019-6340-Drupal-8.6.9-REST-Auth-Bypass

github · Created 2019-02-25 03:38:47 UTC · 2 stars

CVE-2019-6340 Drupal 8.6.9 REST Auth Bypass examples

knqyf263/CVE-2019-6340

github · Created 2019-02-23 13:28:58 UTC · 43 stars

Environment for CVE-2019-6340 (Drupal)

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit