Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6198
HistoryApr 26, 2018 - 10:18 a.m.

Remote Code Execution (RCE)

2018-04-2610:18:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

0.976 High

EPSS

Percentile

100.0%

drupal is vulnerable to remote code execution (RCE) attacks. The library does not properly sanitize URL endpoints where array objects can be supplied to request parameters, allowing a potential compromise of the PHP application, and even the underlying operating system (OS). This vulnerability is related to CVE-2018-7600.