Drupal Core PHP Deserialization Remote Code Execution

Strike ID:
E18-0ouo1
CVSS:
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
12
Year:
2018

Description

This strike exploits a vulnerability in Drupal Core open-source CMS. The vulnerability is due to improper validation of user-supplied data while performing server-side deserialization of PHP objects. A malicious user can exploit this vulnerability by sending multiple HTTP POST requests including serialized PHP objects. When successfuly exploited, the vulnerability results in complete compromise of the target server.

CVE

References

Bid