Junglewise Threat Intelligence

CVE-2020-13671: Drupal core Unrestricted Upload of File with Dangerous Type

CVE-2020-13671 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2021-10-12

Technologies: Drupal Core, drupal/core (Packagist). Vendors: Drupal, Packagist.

Executive brief

Drupal core fails to properly sanitize filenames on uploaded files, allowing files with multiple extensions to bypass security filters. This can lead to files being executed as PHP or served with incorrect MIME types, potentially resulting in remote code execution depending on the hosting configuration.

Affected products

  • Drupal Drupal Core 7 versions prior to 7.74, 8.8 versions prior to 8.8.11, 8.9 versions prior to 8.9.9, 9.0 versions prior to 9.0.8

Timeline

  • 2020-11-18: advisory: Original vendor advisory SA-CORE-2020-012 published
  • 2022-01-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-01-18: disclosed: NVD publication date

Related threats