CVE-2018-7600

critical

Description

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

From the Tenable Blog

Drupalgeddon Attacks Continue on Sites Missing Security Updates (CVE-2018-7600, CVE-2018-7602)
Drupalgeddon Attacks Continue on Sites Missing Security Updates (CVE-2018-7600, CVE-2018-7602)

Published: 2018-11-20

Recent attacks targeting Drupal instances vulnerable to Drupalgeddon 2 and Drupalgeddon 3 highlight the importance of identifying and patching vulnerable sites.

References

https://github.com/Vaibhav91one/drupalgeddon2-cve-lab

https://github.com/514-koishi-514/Kintsugi_CVE

https://github.com/chengbochuan3/CVE-Web-Framework

https://github.com/xiabai2008/poxiao

https://github.com/Athology0000/cve-lab

https://github.com/korneevscp/osint-target

https://github.com/Hector-Abarca/realrisk-checks

https://github.com/Dungsocool/CVE-2018-7600

https://github.com/1392081456/ctf-notes

https://github.com/guilhermeferreira24/healthcare-cybersecurity-analysis

https://github.com/phantom-offensive/AppAssaultLab

https://github.com/Phantom-C2-77/AppAssaultLab

https://github.com/MoriartyPuth-Labs/DC1-Lab

https://github.com/erman-bolukbasi/web-penetration-drupal

https://github.com/Meraj1312/cve-2018-7600-drupalgeddon2-lab

https://github.com/TheMursalin/webscout

https://github.com/Deloney-code/AI-Powered-Red-Team-Automation

https://github.com/nswd332/CVE

https://github.com/CVE-ORG/CVE-ORG

https://github.com/bixiPRO/Drupalgeddon2-CVE-2018-7600

https://github.com/4l13n-DN/POC-CVE-2018-7600

https://github.com/SilentProfessor/Web-vulnerability-testing

https://github.com/tea-celikik/Drupal-Exploit-Lab

https://github.com/xxxTectationxxx/CVE-2018-7600

https://github.com/M-Abid34/CVE-2018-7600

https://github.com/Dowonkwon/drupal-cve-2018-7600-poc

https://github.com/mr-won/CVE-2018-7600.

https://github.com/aadaadaaja508/x-cve

https://github.com/shacojx/Drupal-CVE-Exploit-POC

https://github.com/VictorMora97/Drupalgeddon2

https://github.com/ludy-dev/drupal8-REST-RCE

https://github.com/ynsmroztas/drupalhunter

https://github.com/rabbitmask/CVE-2018-7600-Drupal7

https://github.com/zhzyker/CVE-2018-7600-Drupal-POC-EXP

https://github.com/shellord/Drupalgeddon-Mass-Exploiter

https://github.com/drugeddon/drupal-exploit

https://github.com/madneal/codeql-scanner

https://github.com/Damian972/drupalgeddon-2

https://github.com/Hestat/drupal-check

https://github.com/lorddemon/drupalgeddon2

https://github.com/pimps/CVE-2018-7600

https://github.com/firefart/CVE-2018-7600

https://github.com/FireFart/CVE-2018-7600

https://github.com/sl4cky/CVE-2018-7600-Masschecker

https://github.com/sl4cky/CVE-2018-7600

https://github.com/knqyf263/CVE-2018-7600

https://www.drupal.org/sa-core-2018-002

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-7600

https://twitter.com/RicterZ/status/984495201354854401

https://twitter.com/RicterZ/status/979567469726613504

https://research.checkpoint.com/uncovering-drupalgeddon-2/

https://groups.drupal.org/security/faq-2018-002

https://greysec.net/showthread.php?tid=2912&pid=10561

https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/

http://www.securitytracker.com/id/1040598

http://www.securityfocus.com/bid/103534

Details

Source: Mitre, NVD

Published: 2018-03-29

Updated: 2026-06-17

Named Vulnerability: Drupalgeddon2Named Vulnerability: Drupalgeddon 2Named Vulnerability: DrupalgeddonKnown Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99991