TROYANOSYVIRUS
Volver a CVEs

CVE-2020-13671

HIGHCISA KEV
8.8

Descripcion

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

Detalles CVE

Puntuacion CVSS v3.18.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado11/20/2020
Ultima modificacion11/3/2025
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorDrupal
ProductoDrupal core
Nombre vulnerabilidadDrupal core Un-restricted Upload of File
Fecha inclusion KEV2022-01-18
Fecha limite remediacion2022-07-18
Uso en ransomwareUnknown

Productos afectados

drupal:drupalfedoraproject:fedora

Debilidades (CWE)

CWE-434CWE-434

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.