PT-2020-4195 · Drupal · Drupal Core

Lorenzo G

+1

·

Published

2020-06-17

·

Updated

2024-03-06

·

CVE-2020-13664

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Drupal Core versions prior to 8.8.8 Drupal Core versions prior to 8.9.1 Drupal Core version 9.0.1
Description: The issue is related to an arbitrary PHP code execution vulnerability under certain circumstances. An attacker could trick an administrator into visiting a malicious site, resulting in the creation of a carefully named directory on the file system. With this directory in place, an attacker could attempt to brute force a remote code execution vulnerability. This issue is most likely to affect Windows servers. The vulnerability is associated with insufficient authentication of executed requests, which could allow a remote attacker to execute arbitrary code.
Recommendations: For Drupal Core versions prior to 8.8.8, update to version 8.8.8 or later. For Drupal Core versions prior to 8.9.1, update to version 8.9.1 or later. For Drupal Core version 9.0.1, update to a version later than 9.0.1. As a temporary workaround, consider restricting access to the file system to minimize the risk of exploitation.

Exploit

Fix

RCE

CSRF

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2020-04629
BIT-DRUPAL-2020-13664
CVE-2020-13664
DRUPAL-CORE-2020-005
GHSA-X72F-GGJW-V5XH

Affected Products

Drupal Core