Skip to content
COOEY

EXPOSURES › CVE-2019-6340

CVE-2019-6340

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-6340 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Drupal Core's improper data sanitization allowed arbitrary PHP code execution via non-form sources.

Drupal Core failed to sanitize data from non-form sources, enabling arbitrary PHP code execution. DIB orgs must ensure CMS platforms are patched against actively exploited CVEs like this one, as unpatched vulnerabilities can lead to ransomware or data breaches. Always verify that software is not on CISA's KEV list.

Shame score — A core CMS vulnerability that was actively exploited in the wild, indicating negligent patching and a failure to protect against known threats.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.