CISA description
Improper sanitization in the extension file names is present in Drupal core.
Drupal · Drupal core
Drupal core Un-restricted Upload of File
Improper sanitization in the extension file names is present in Drupal core.
Apply updates per vendor instructions.
Vulnerability data triggers these controls during assessment and continuous monitoring.