-
CVSS Score
-The vulnerability description directly references DefaultMailSystem::mail as the source of the vulnerability. The function's role in handling email and potentially unsanitized user input makes it a critical point for remote code execution vulnerabilities.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| drupal/core | composer | >= 7.0, < 7.60 | 7.60 |
| drupal/core | composer | >= 8.0.0, < 8.5.8 | 8.5.8 |
| drupal/core |
| composer |
| >= 8.6.0, < 8.6.2 |
| 8.6.2 |
Ongoing coverage of React2Shell