CVE detail
CVE-2019-6340: Drupal Core Remote Code Execution Vulnerability
Source: CISA Known Exploited Vulnerabilities catalog · back to feed
Vendor / product
Drupal · Core
- Date added (KEV)
- Mar 25, 2022
- CISA due date
- Apr 15, 2022
- Ransomware campaign use
- Unknown
Scorifya interpretation
AI-generatedA short, structured read of the record above, generated when this page first loads, then cached for a week.
Plain English
Technical detail
From CISA
In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
https://nvd.nist.gov/vuln/detail/CVE-2019-6340
See what attackers can see on your domain
This vulnerability is on CISA's Known Exploited Vulnerabilities list, so it is being exploited in the wild right now. Scorifya can't test for Drupal directly, but in about 30 seconds it shows what your own domain exposes publicly across TLS, security headers, DNS, and cookies: the surface attackers probe first.
SOC 2 compliance
Tracking remediation across your cloud infrastructure?
Scorifya Controls automates 54 SOC 2 checks across AWS, GitHub, GCP, and Azure, and gives you a manual evidence trail for the controls no tool can automate. Self-hosted, three tiers from $99/mo.
See Scorifya Controls →References
- https://www.drupal.org/sa-core-2019-003MitigationVendor Advisory
- https://www.drupal.org/sa-core-2019-003MitigationVendor Advisory
- https://www.exploit-db.com/exploits/46452/PatchThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46452/PatchThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/107106Broken LinkThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46459/ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46510/ExploitThird Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_09Third Party Advisory
- http://www.securityfocus.com/bid/107106Broken LinkThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46459/ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46510/ExploitThird Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_09Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-6340US Government Resource
Other recent CVEs from Drupal
- CVE-2026-9082Core, Drupal Core SQL Injection Vulnerability
- CVE-2018-7602Core, Drupal Core Remote Code Execution Vulnerability
- CVE-2020-13671Drupal core, Drupal core Un-restricted Upload of File
- CVE-2018-7600Drupal Core, Drupal Core Remote Code Execution Vulnerability