Loading HuntDB...

Drupal Core Remote Code Execution Vulnerability

Added March 25, 2022 Due April 15, 2022 CVE-2019-6340
Overdue Drupal / Core CWE-502

Description

In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
4 months, 3 weeks ago