EXPOSURES › CVE-2020-13671
CVE-2020-13671
HIGH ⌖ ON CISA KEV · EXPLOITEDDrupal core's improper extension file name sanitization allows un-restricted file uploads, enabling attackers to execute arbitrary code on vulnerable systems.
Drupal core's CVE-2020-13671 involves improper sanitization of extension file names, allowing un-restricted file uploads that can lead to remote code execution. DIB organizations must vigilantly patch Drupal core and vet extensions to prevent exploitation, as this vulnerability is actively exploited in the wild. Failure to patch promptly exposes systems to ransomware and data breaches, violating CMMC/NIST 800-171 requirements for timely vulnerability management.
Shame score — Drupal core's history of critical RCE vulnerabilities, including CVE-2018-7600 exploited by ransomware, combined with CVE-2020-13671 being actively exploited in the wild, demonstrates severe negligence in patching and extension vetting.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Improper sanitization in the extension file names is present in Drupal core.