PromptRiskDBThreat intelligence atlas

CVE-2020-13671 - Drupal Drupal core

AI Vulnerability Context

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

Overview

A source-backed snapshot of this vulnerability.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEVHIGH
CVE ID
CVE-2020-13671
Vendor/project
Drupal
Product
Drupal core
Vulnerability name
Drupal core Un-restricted Upload of File
Date added
2022-01-18
Due date
2022-07-18
Known ransomware campaign use
Unknown
CVSS v3
8.8
CWE-434

Exploit context

What the vulnerability is about.

No description available. The source record only contains identifiers and metadata.

Source evidence

Original public records and references for this page.

Original source

Original source links

Open the public records and source datasets used for this page.