Back to CVE Lookup
CVE-2018-7600
CRITICAL - CVSS 9.8CWE-20
Published: 3/29/2018
Modified: 10/31/2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
Vulnerability Summary
CVSS v3 Score
9.8CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2 Score
7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P