Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade drupal7 | Aug 22, 2024 | Nov 20, 2020 |
| Debian | — | Upgrade drupal7 | Nov 20, 2020 | Nov 20, 2020 |
| Drupal | — | Upgrade to drupal version 8.8.1Upgrade to drupal version 8.9.9Upgrade to drupal version 7.74Upgrade to drupal version 9.0.8 | Nov 19, 2020 | Nov 19, 2020 |
| Ubuntu | — | Upgrade drupal7 (Ubuntu Pro) | Aug 28, 2024 | Nov 20, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub