Vulnerability Bulletins |
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002 |
|
| Affected software | Drupal |
|
Project: Drupal coreDate: 2018-March-28Security risk: Highly critical 22∕25 AC:None/A:None/CI:All/II:All/E:Proof/TD:DefaultVulnerability: Remote Code Execution Description: CVE: CVE-2018-7600A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being completely compromised.The security team has written an FAQ about this More info: https://www.drupal.org/sa-core-2018-002 |
|






