CISA Known Exploited Vulnerability

CVE-2020-13671

Drupal · Drupal core

Drupal core Un-restricted Upload of File

Date added
BOD 22-01 due date
CWE CWE-434
Ransomware Unknown

CISA description

Improper sanitization in the extension file names is present in Drupal core.

Required action

Apply updates per vendor instructions.