CVE-2020-13671 is a critical vulnerability in Drupal core affecting versions prior to 9.0.8, 8.9.9, 8.8.11, and 7.74. It stems from improper filename sanitization of uploaded files, allowing them to be misinterpreted and potentially executed as PHP, leading to remote code execution. With a CVSS score of 8.8 (High), this vulnerability is easily exploitable over the network with low privileges, enabling full compromise of confidentiality, integrity, and availability. This flaw is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered significant media attention and community discussion, despite the lack of public exploit code on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0, < 7.74CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | ||
>= 8.8.0, < 8.8.11CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | ||
>= 8.9.0, < 8.9.9CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.8CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.