EXPOSURES › CVE-2019-6340
CVE-2019-6340
HIGH ⌖ ON CISA KEV · EXPLOITEDDrupal Core's improper data sanitization allowed arbitrary PHP code execution via non-form sources.
Drupal Core failed to sanitize data from non-form sources, enabling arbitrary PHP code execution. DIB orgs must ensure CMS platforms are patched against actively exploited CVEs like this one, as unpatched vulnerabilities can lead to ransomware or data breaches. Always verify that software is not on CISA's KEV list.
Shame score — A core CMS vulnerability that was actively exploited in the wild, indicating negligent patching and a failure to protect against known threats.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.