CVE-2020-13671
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Drupal core Un-restricted Upload of File
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 4% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-434
מוצרים מושפעים
drupal: drupal; fedoraproject: fedora
קישורים
- https://www.drupal.org/sa-core-2020-012 Vendor Advisory
- https://www.drupal.org/sa-core-2020-012 Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Mailing ListRelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Mailing ListRelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Mailing ListRelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Mailing ListRelease Notes
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource