CVE-2020-13671
Drupal core Un-restricted Upload of File
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.
HIGH · CVSS 8.8
⚠ CISA KEV
EPSS 0.04504
Act now
- Listed on CISA KEV (known exploited in the wild)
- SSVC exploitation status: active
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0