Drupal Core Remote Code Execution Vulnerability (CVE-2020-13671)

Overview On 18 November 2020, Drupal released an  advisory for critical Remote Code Execution Vulnerability (CVE-2020-13671).  Successful exploitation of this vulnerability may allow attackers to take over vulnerable sites. The bug exists in Drupal core due to improper sanitization of certain filenames on uploaded files. This results in the files being interpreted as an invalid extension and can be treated as a wrong MIME … Continue reading “Drupal Core Remote Code Execution Vulnerability (CVE-2020-13671)”