CVE-2020-13664: Command Injection
Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker could attempt to brute force a remote code execution vulnerability. Windows servers are most likely to be affected. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.1 versions prior to 9.0.1.
Other sources
Drupal core - Critical - Arbitrary PHP code execution - SA-CORE-2020-005
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13664?
The severity of CVE-2020-13664 is critical.
How does the vulnerability in CVE-2020-13664 allow arbitrary PHP code execution?
The vulnerability in CVE-2020-13664 allows an attacker to trick an administrator into visiting a malicious site, resulting in the execution of arbitrary PHP code.
Which versions of Drupal Core are affected by CVE-2020-13664?
Versions of Drupal Core from 8.0.0 to 8.9.1 and 9.0.0 to 9.0.1 are affected by CVE-2020-13664.
How can I fix the vulnerability in CVE-2020-13664?
To fix the vulnerability in CVE-2020-13664, update Drupal Core to a version that includes the patch provided by the official security advisory (SA-CORE-2020-005).
Where can I find more information about CVE-2020-13664?
More information about CVE-2020-13664 can be found in the official security advisory (SA-CORE-2020-005) on the Drupal website.