Detects Drupal instances where the REST API with HAL module accepts unauthenticated requests. Versions 8.5.x before 8.5.11 and 8.6.x before 8.6.10 deserialize attacker-controlled PHP objects from HAL+JSON input, enabling remote code execution without authentication.
Is your app exploitable through CVE-2019-6340?
Scan your domain free