DRUPAL-CONTRIB-2018-055

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/phpconfig/DRUPAL-CONTRIB-2018-055.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2018-055
Published
2018-08-08T17:14:32Z
Modified
2025-12-10T23:29:03.687454Z
Summary
[none]
Details

This module enables you to add or overwrite PHP configuration on a drupal website.

The module doesn't sufficiently allow access to set these configurations, leading to arbitrary PHP configuration execution by an attacker.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer phpconfig".

After updating the module, it's important to review the permissions of your website and if 'administer phpconfig' permission is given to a not fully trusted user role, we advise to revoke it.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/phpconfig

Package

Name
drupal/phpconfig
Purl
pkg:composer/drupal/phpconfig

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.0
Database specific
{
    "constraint": "<1.1.0"
}

Database specific

affected_versions
"<1.1.0"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/phpconfig/DRUPAL-CONTRIB-2018-055.json"