Record summary

CVE-2020-13671 has a selected CVSS score of 8.8 (high). CISA lists CVE-2020-13671 in KEV; VulnCheck reports CVE-2020-13671 use in known ransomware campaigns.

Description

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Jan 18, 2022 · CISA
VulnCheck KEV
Listed · Apr 12, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2025 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
VulnCheck, CVE List, CISA9.0 versions prior to 9.0.8affected
8.9 versions prior to 8.9.9affected
8.8 versions prior to 8.8.11affected
7 versions prior to 7.74affected
GitHub Advisory9.0.0 to < 9.0.8 · Fixed in 9.0.8affected
8.9.0 to < 8.9.9 · Fixed in 8.9.9affected
8.0.0 to < 8.8.11 · Fixed in 8.8.11affected
7.0.0 to < 7.74 · Fixed in 7.74affected
GitHub Advisory7.0.0 to < 7.74 · Fixed in 7.74affected
8.0.0 to < 8.8.11 · Fixed in 8.8.11affected
8.9.0 to < 8.9.9 · Fixed in 8.9.9affected
9.0.0 to < 9.0.8 · Fixed in 9.0.8affected

References

10