Educational CVE-2018-7600 exploit project combining a Python RCE PoC, isolated Docker Drupal lab, payload research, and mitigation documentation for safe vulnerable-application testing.
This project researches, replicates, and documents CVE-2018-7600 (Drupalgeddon2) — a Critical (CVSS 9.8) unauthenticated Remote Code Execution vulnerability in Drupal CMS, affecting versions prior to 7.58 and 8.5.1 (released March 2018).
The vulnerability exists in Drupal's Form API, which failed to sanitize user-supplied input before merging it into form element render properties — allowing attackers to inject PHP callables that the Render API would then execute.
⚠️ For educational use only. All testing must be performed exclusively against the isolated Docker lab environment. Never test on live or production systems.
| Member | Role | Deliverables |
|---|---|---|
| Member 1 | Lab Environment & CVE Verification | Dockerfile, docker-compose, SETUP.md |
| Member 2 | Exploit Development | exploit.py framework, payloads.txt |
| Member 3 | Root Cause Analysis & Research | root_cause_analysis.md, references.md, mitigation.md |
| Member 4 | Proof Collection & Final Report | terminal_logs.txt, screenshots, final report |
CVE-2018-7600-Project/
│
├── README.md ← you are here
│
├── lab/ ← Member 1
│ ├── Dockerfile ← builds Drupal 7.57 image
│ ├── docker-compose.yml ← orchestrates all services
│ ├── entrypoint.sh ← DB wait + auto-config script
│ ├── SETUP.md ← step-by-step setup guide
│ └── config_notes.md ← vulnerability verification
│
├── exploit/ ← Member 2
│ ├── exploit.py ← PoC Python framework
│ └── payloads.txt ← payload research notes
│
├── docs/ ← Member 3
│ ├── root_cause_analysis.md ← technical deep-dive
│ ├── references.md ← all sources & links
│ └── mitigation.md ← patch & hardening guide
│
├── proof/ ← Member 4
│ ├── screenshots/ ← exploitation screenshots
│ └── terminal_logs.txt ← command output logs
│
└── report/
└── CVE-2018-7600_Report.docx ← Member 4: final report
cd lab/
docker compose up -d --build
Open http://localhost:8080/install.php and follow SETUP.md Step 3.
curl -s http://localhost:8080/CHANGELOG.txt | head -3
# Expected: Drupal 7.57, 2018-02-21
cd .. # project root
python exploit/exploit.py --target http://localhost:8080 --safe-mode
python exploit/exploit.py --target http://localhost:8080 --cmd "id"
python exploit/exploit.py --target http://localhost:8080 --cmd "id" \
--output proof/terminal_logs.txt
cd lab/
docker compose down -v && docker compose up -d --build
| Property | Value |
|---|---|
| CVE ID | CVE-2018-7600 |
| Nickname | Drupalgeddon2 |
| Vendor Advisory | SA-CORE-2018-002 |
| CVSS v3 | 9.8 Critical |
| Affected | Drupal < 7.58, < 8.3.9, < 8.4.6, < 8.5.1 |
| Fixed in | 7.58, 8.3.9, 8.4.6, 8.5.1 |
| Auth Required | No |
| Type | Remote Code Execution |
ITSOLERA Red Team Internship — Summer 2026