CVE-2019-6340

unknown KEV
Published 2019-02-20 · Modified 2022-03-25
CVSS v3
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H
CVSS v2
VIR risk
1.5

Description

In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

CISA KEV

Vendor
Drupal
Product
Core
Due date
2022-04-15

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://nvd.nist.gov/vuln/detail/CVE-2019-6340

Exploits

Package impact

EcosystemPackageVulnerableFixed
php Packagistdrupal/core>=8.0.0,<8.5.11||>=8.6.0,<8.6.108.5.11
php Packagistdrupal/core>=8.6.0,<8.6.108.6.10
php Packagistdrupal/core>=7.0.0,<7.62.07.62.0
php Packagistdrupal/core>=8.0.0,<8.5.118.5.11
php Packagistdrupal/drupal>=7.0.0,<7.62.07.62.0
php Packagistdrupal/drupal>=8.0.0,<8.5.118.5.11
php Packagistdrupal/drupal>=8.6.0,<8.6.108.6.10

References

Verify integrity in audit chain (admin only). AS-IS.