References https://nvd.nist.gov/vuln/detail/CVE-2019-6340 https://www.drupal.org/sa-core-2019-003 https://www.rapid7.com/blog/post/2019/02/21/cve-2019-6340-drupal-core-remote-code-execution-what-you-need-to-know/ https://www.exploit-db.com/exploits/46452/ https://www.exploit-db.com/exploits/46510 https://blog.lexfo.fr/drupal8-rce.html https://www.trendmicro.com/en_us/research/19/b/drupal-vulnerability-cve-2019-6340-can-be-exploited-for-remote-code-execution.html https://beaglesecurity.com/blog/vulnerability/drupal-8-core-restful-web-services-rce.html https://github.com/knqyf263/CVE-2019-6340 https://security.snyk.io/vuln/SNYK-PHP-DRUPALCORE-173723
Related VulnerabilitiesPoCmonitorr-file-upload: Monitorr Services Configuration - Arbitrary File UploadPoCCVE-2026-10768: Drupal LocalGov Workflows < 1.6.0 - Information Disclosure金蝶EAS /ormrpc/services/BSHService 代码执行漏洞广联达OA /Mail/Services/EmailAccountOrgUserService.asmx/GetUserEmailByOrgEmails XML 外部实体注入漏洞广联达OA /GTP/IM/Services/Group/Broadcast/MsgBroadcastContent.aspx SQL 注入漏洞宏景eHR /services/SynToADService XML 外部实体注入漏洞PoCCVE-2026-9082: Drupal Core - Anonymous SQL Injection via PostgreSQL Entity QueryDrupal core /jsonapi/node/article SQL 注入漏洞(CVE-2026-9082)宏景 eHR /services/HrChangeInfoService XML 外部实体注入漏洞联软安渡UniNXG /UniExServices/link/queryLinklnfo SQL 注入漏洞泛微E-Cology9 /services/WorkPlanService SQL 注入漏洞Alfresco Content Services /alfresco/service/api/login 默认口令漏洞深信服运维安全管理系统 /fort/outServices;help/generate_certificate 命令执行漏洞