CVE-2018-7602 is a highly critical remote code execution (RCE) vulnerability affecting multiple subsystems of Drupal 7.x and 8.x, allowing attackers to fully compromise affected websites. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and no required user interaction or privileges. This vulnerability is actively exploited in the wild, including in known ransomware campaigns, and has readily available exploit code and significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0, < 7.59CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | ||
>= 8.4.0, < 8.4.8CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | ||
>= 8.5.0, < 8.5.3CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.