7.5
CVSSv2

CVE-2020-13675

Published: 11/02/2022 Updated: 18/02/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by modules on the site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal

Vendor Advisories

Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs The modules do not correctly run all file validation, which causes an access bypass vulnerability An attacker might be able to upload files that bypass the file validation process implemented by modules on the site This vulnerability is mitigated by three factors ...