CyberSec.Space Logo
返回 CVE 浏览器

CVE-2020-13671

🔥 Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
EPSS Score52.6370%
EPSS Percentile85.37th
Published2020-11-20
Last Modified2025-11-03
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

Affected Platforms (CPE)

📦
Drupal

Drupal

>= 7.0 and < 7.74>= 8.8.0 and < 8.8.11>= 8.9.0 and < 8.9.9>= 9.0.0 and < 9.0.8
💻
Fedoraproject

Fedora

= 32= 33

References & Advisories

相关漏洞威胁