All verified exploits

CVE-2019-6340 REST API Deserialization RCE

Deterministic critical Drupal CISA KEV Added cve-verified-cve-2019-6340

Detects Drupal instances where the REST API with HAL module accepts unauthenticated requests. Versions 8.5.x before 8.5.11 and 8.6.x before 8.6.10 deserialize attacker-controlled PHP objects from HAL+JSON input, enabling remote code execution without authentication.

Related Drupal exploits

Is your app exploitable through CVE-2019-6340?

Scan your domain free