Логотип exploitDog
bind:CVE-2020-13675
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-13675

Количество 2

Количество 2

nvd логотип

CVE-2020-13675

больше 3 лет назад

Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by modules on the site.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-v8wr-r69p-mmwx

больше 3 лет назад

Unrestricted Upload of File with Dangerous Type in Drupal core

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-13675

Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by modules on the site.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-v8wr-r69p-mmwx

Unrestricted Upload of File with Dangerous Type in Drupal core

CVSS3: 9.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу