Skip to content
COOEY

EXPOSURES › CVE-2020-13671

CVE-2020-13671

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-13671 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatchedransomware

Drupal core's improper extension file name sanitization allows un-restricted file uploads, enabling attackers to execute arbitrary code on vulnerable systems.

Drupal core's CVE-2020-13671 involves improper sanitization of extension file names, allowing un-restricted file uploads that can lead to remote code execution. DIB organizations must vigilantly patch Drupal core and vet extensions to prevent exploitation, as this vulnerability is actively exploited in the wild. Failure to patch promptly exposes systems to ransomware and data breaches, violating CMMC/NIST 800-171 requirements for timely vulnerability management.

Shame score — Drupal core's history of critical RCE vulnerabilities, including CVE-2018-7600 exploited by ransomware, combined with CVE-2020-13671 being actively exploited in the wild, demonstrates severe negligence in patching and extension vetting.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Improper sanitization in the extension file names is present in Drupal core.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.