First published: Wed Jun 17 2020(Updated: )
Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker could attempt to brute force a remote code execution vulnerability. Windows servers are most likely to be affected. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.1 versions prior to 9.0.1.
Credit: mlhess@drupal.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/core | >=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.6.0>=8.6.0<8.7.0>=8.7.0<8.8.0>=8.8.0<8.8.8>=8.9.0<8.9.1>=9.0.0<9.0.1 | |
composer/drupal/drupal | >=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.6.0>=8.6.0<8.7.0>=8.7.0<8.8.0>=8.8.0<8.8.8>=8.9.0<8.9.1>=9.0.0<9.0.1 | |
Drupal Drupal | >=8.8.0<8.8.8 | |
Drupal Drupal | >=8.9.0<8.9.1 | |
Drupal Drupal | >=9.0.0<9.0.1 | |
composer/drupal/drupal | >=9.0.0<9.0.1 | 9.0.1 |
composer/drupal/drupal | >=8.9.0<8.9.1 | 8.9.1 |
composer/drupal/drupal | >=8.8.0<8.8.8 | 8.8.8 |
composer/drupal/core | >=9.0.0<9.0.1 | 9.0.1 |
composer/drupal/core | >=8.9.0<8.9.1 | 8.9.1 |
composer/drupal/core | >=8.8.0<8.8.8 | 8.8.8 |
>=8.8.0<8.8.8 | ||
>=8.9.0<8.9.1 | ||
>=9.0.0<9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-13664 is critical.
The vulnerability in CVE-2020-13664 allows an attacker to trick an administrator into visiting a malicious site, resulting in the execution of arbitrary PHP code.
Versions of Drupal Core from 8.0.0 to 8.9.1 and 9.0.0 to 9.0.1 are affected by CVE-2020-13664.
To fix the vulnerability in CVE-2020-13664, update Drupal Core to a version that includes the patch provided by the official security advisory (SA-CORE-2020-005).
More information about CVE-2020-13664 can be found in the official security advisory (SA-CORE-2020-005) on the Drupal website.