CVE-2020-13664
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
05/05/2021
Last modified:
14/05/2021
Description
Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker could attempt to brute force a remote code execution vulnerability. Windows servers are most likely to be affected. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.1 versions prior to 9.0.1.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | 8.8.0 (including) | 8.8.8 (excluding) |
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | 8.9.0 (including) | 8.9.1 (excluding) |
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | 9.0.0 (including) | 9.0.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page