Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.
We have discovered 110,467 live websites that are affected by CVE-2020-13671.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 110,467 live websites (54% of Drupal install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 128 versions ( 37% of all versions) |
| 28,243 websites | |
| 10,613 websites | |
| 10,244 websites | |
| 8,374 websites | |
| 4,147 websites | |
| 3,947 websites | |
| 3,632 websites | |
| 3,047 websites | |
| 2,837 websites | |
| 2,776 websites |
| .com | 30,032 websites |
| .org | 9,217 websites |
| .ru | 8,245 websites |
| .de | 6,198 websites |
| .fr | 4,125 websites |
| .be | 3,416 websites |
| .it | 3,038 websites |
| .net | 2,731 websites |
| .nl | 2,197 websites |
| .edu | 1,979 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.gov | *,*** | ||
| ***.**.gov | *,*** | ||
| ****.org | *,*** | ||
| *******.com | *,*** | ||
| ******.org | *,*** | ||
| *******.org | *,*** | ||
| *****************.org | *,*** | ||
| *******.org | *,*** | ||
| ***************.********.gov | *,*** | ||
| *****.org | *,*** |