CVE-2018-7602
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
- Published
- Jul 19, 2018
- Updated
- Aug 13, 2026
- Assigning CNA
- drupal
- Evidence observed
- Apr 25, 2018
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.
Sources
10- Drupalgedon3PoC
POC to test/exploit drupal vulnerability SA-CORE-2018-004 / CVE-2018-7602
- DrupalCVE-2018-7602Exploit
Exploit for Drupal CVE-2018-7602 remote code execution vulnerability via double URL encoding bypass of sanitize() filter. Includes Docker-based lab environment and PoC script for penetration testing.
- CVE-2018-7602Exploit
Drupalgeddon3 RCE exploit lab with Docker-based vulnerable environment and Metasploit integration for hands-on CVE-2018-7602 exploitation training.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.