S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-6340 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in Drupal Core affects v. 8.5.x before 8.5.11 and 8.6.x before 8.6.10.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2019-6340
8.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Drupal Coreby Drupal
AFFECTED< 8.5.11SAFE ✓≥ 8.5.11
Updated Aug 21, 2026View on NVD →
Detail

Drupal Core is a highly renowned content management system (CMS) that enables users to create dynamic and interactive websites with ease. The CMS is used by millions of users worldwide for various purposes such as e-commerce, government portals, social networking, etc. It has a vast array of features built-in and offers additional functionality through various third-party modules. The CMS is free, open-source, and licensed under GPLv2. 

The CVE-2019-6340 vulnerability detected in Drupal Core can allow arbitrary PHP code execution in some cases. It occurs due to the improper sanitization of data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This vulnerability can impact sites that have the Drupal 8 core RESTful Web Services (rest) module enabled and that allow PATCH or POST requests or have another web services module enabled such as JSON:API in Drupal 8 or Services or RESTful Web Services in Drupal 7. 

Exploiting this vulnerability can lead to unauthorized code execution, which can cause significant harm to the system, including theft of sensitive data, modification of data, and complete takeover of the site. The potential attacker only needs to send a maliciously crafted request to the targeted server to carry out this attack. 

At s4e.io, we understand the importance of having a secure digital environment. Our platform offers advanced security features to help users identify and mitigate vulnerabilities in their digital assets easily and quickly. With the help of our comprehensive security scans, users can identify critical security issues in their systems and take proactive measures to prevent potential attacks. Stay secure with s4e.io.

 

REFERENCES

Solution Advice

To mitigate the risks associated with CVE-2019-6340, users must update their systems to the latest version of Drupal Core, which contains the necessary fixes. Additionally, it is recommended to follow the below precautions:

  • Disable RESTful Web Services, JSON:API, Services, or other web services modules that are not required.
  • Restrict access to vulnerable endpoints.
  • Use a Web Application Firewall (WAF) to prevent unauthorized requests from reaching the system.
  • Regularly scan systems for vulnerabilities using security assessment tools.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-6340 scanner - Remote Code Execution (RCE) vulnerability in Drupal Core | S4E