Sploitus

CVE-2019-6340

34 known exploits for CVE-2019-6340

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)

Affected products
Drupal
Drupal
< 8.5.11, 8.6.10
Fix
Available
CVSS 3.1
8.1 HIGH
EPSS
92.0% (100th percentile)
Weakness
CWE-502
NVD status
Analyzed
Published
2019-02-21
CVE-2019-6340 at NVD
Authoritative description, scoring and affected products

34 known exploits for CVE-2019-6340

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2019-6340
2026-08-27 KitPloitKITPLOIT
Drupal-SA-CORE-2019-003
2026-08-27 KitPloitKITPLOIT
CVE-2019-6340
2026-08-27 KitPloitKITPLOIT
CVE-2019-6340
2026-08-27 KitPloitKITPLOIT
CVE-2019-6340-Drupal-8.6.9-REST-Auth-Bypass
2026-08-26 KitPloitKITPLOIT
Drupal-cve-2019-6340
2026-08-26 KitPloitKITPLOIT
cve-2019-6340
2026-08-26 KitPloitKITPLOIT
CVE-2019-6340
2026-08-26 KitPloitKITPLOIT
drupal8-REST-RCE
2026-08-26 KitPloitKITPLOIT
cve-2019-6340-bits
2026-08-25 KitPloitKITPLOIT
Drupal_REST-RCE_Unauthenticated
2026-08-25 KitPloitKITPLOIT
Exploit for Deserialization of Untrusted Data in Drupal
2026-05-27 joaoaugustomGITHUB
Exploit for Deserialization of Untrusted Data in Drupal
2021-05-01 nobodyatall648GITHUB
Exploit for Improper Input Validation in Drupal
2020-08-31 ludy-devGITHUB
Exploit for Deserialization of Untrusted Data in Drupal
2019-05-27 jas502nGITHUB
Drupal < 8.5.11 / < 8.6.10 - RESTful Web Services unserialize() Remote Command Execution (Metasploit)
2019-03-07 MetasploitEXPLOITDBRuby
Drupal RESTful Web Services unserialize() Remote Code Execution Exploit
2019-03-06 wvuZDTRuby
Drupal RESTful Web Services unserialize() Remote Code Execution
2019-03-06 wvuPACKETSTORMRuby
Drupal REST module command execution
2019-02-27 SAINT CorporationSAINT
Drupal REST module command execution
2019-02-27 SAINT CorporationSAINT
Drupal REST module command execution
2019-02-27 SAINT CorporationSAINT
Drupal < 8.6.9 - REST Module Remote Code Execution Exploit
2019-02-25 leonjzaZDTPython
Drupal 8.6.9 - REST Module Remote Code Execution
2019-02-25 leonjzaEXPLOITPACKPython
Drupal < 8.6.9 - REST Module Remote Code Execution
2019-02-25 leonjzaEXPLOITDBPython
Exploit for Deserialization of Untrusted Data in Drupal
2019-02-25 DevDungeonGITHUB
Exploit for Deserialization of Untrusted Data in Drupal
2019-02-25 owaysGITHUB
Drupal 8.6.9 REST Remote Code Execution
2019-02-25 leonjzaPACKETSTORM
Drupal < 8.6.10 / < 8.5.11 - REST Module Remote Code Execution Vulnerability
2019-02-24 Charles FolZDT
Drupal < 8.6.10 / < 8.5.11 - REST Module Remote Code Execution
2019-02-23 Charles FolEXPLOITDB
Drupal REST Module Remote Code Execution
2019-02-23 Charles FOLPACKETSTORM
Exploit for Deserialization of Untrusted Data in Drupal
2019-02-22 g0rxGITHUB
CVE-2019-6340
2019-02-21 drupalUNKNOWN
Immunity Canvas: DRUPAL_SERVICES_RCE
2019-02-21 Immunity CanvasCANVAS
Drupal RESTful Web Services unserialize() RCE
2019-02-20 Jasper Mattsson, Charles Fol, Rotem Reiss, wvu <wvu@metasploit.com>METASPLOITRuby