SA-CORE-2018-004: Critical severity Drupal Drupal Core vulnerability
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild. Updated — this vulnerability is being exploited in the wild.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of SA-CORE-2018-004?
SA-CORE-2018-004 is classified as a highly critical remote code execution vulnerability.
How do I fix SA-CORE-2018-004?
To fix SA-CORE-2018-004, update your Drupal installation to the latest versions of 7.x or 8.x as recommended in the advisory.
Which versions are affected by SA-CORE-2018-004?
SA-CORE-2018-004 affects Drupal versions 7.x from 7.0 and 8.x from 8.0.
What are the risks associated with SA-CORE-2018-004?
Exploiting SA-CORE-2018-004 can allow attackers to execute arbitrary code, potentially compromising the entire Drupal site.
Are there known exploits for SA-CORE-2018-004?
Yes, there are known exploits for SA-CORE-2018-004 that target various subsystems in Drupal.