github.com
https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2020-13671.yaml CVE-2020-13671
HIGHCISA KEVRansomware
Drupal core Unrestricted Upload of File with Dangerous Type
Record summary
CVE-2020-13671 has a selected CVSS score of 8.8 (high). CISA lists CVE-2020-13671 in KEV; VulnCheck reports CVE-2020-13671 use in known ransomware campaigns.
Description
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Jan 18, 2022 · CISA
- VulnCheck KEV
- Listed · Apr 12, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Drupal CoreBrowse Drupal / Drupal Core | VulnCheck, CVE List, CISA | 9.0 versions prior to 9.0.8 | affected |
| 8.9 versions prior to 8.9.9 | affected | ||
| 8.8 versions prior to 8.8.11 | affected | ||
| 7 versions prior to 7.74 | affected | ||
drupal/coreBrowse Packagist / drupal/core | GitHub Advisory | 9.0.0 to < 9.0.8 · Fixed in 9.0.8 | affected |
| 8.9.0 to < 8.9.9 · Fixed in 8.9.9 | affected | ||
| 8.0.0 to < 8.8.11 · Fixed in 8.8.11 | affected | ||
| 7.0.0 to < 7.74 · Fixed in 7.74 | affected | ||
drupal/drupalBrowse Packagist / drupal/drupal | GitHub Advisory | 7.0.0 to < 7.74 · Fixed in 7.74 | affected |
| 8.0.0 to < 8.8.11 · Fixed in 8.8.11 | affected | ||
| 8.9.0 to < 8.9.9 · Fixed in 8.9.9 | affected | ||
| 9.0.0 to < 9.0.8 · Fixed in 9.0.8 | affected |
References
10github.com
https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2020-13671.yaml github.com
https://github.com/drupal/core FEDORA-2020-d50d74d6f2Vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5KSFM672XW3X6BR7TVKRD63SLZGKK437 FEDORA-2020-6f1079934cVendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KWM4CTMEGAC4I2CHYNJVSROY4CVXVEUT lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5KSFM672XW3X6BR7TVKRD63SLZGKK437 lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KWM4CTMEGAC4I2CHYNJVSROY4CVXVEUT nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-13671 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-13671 drupal.orgConfirmation
https://www.drupal.org/sa-core-2020-012