Boletines de Vulnerabilidades |
Drupal core - Critical - Arbitrary PHP code execution - SA-CORE-2020-005 |
|
| Software afectado | Drupal |
|
Project: Drupal coreDate: 2020-June-17Security risk: Critical 17∕25 AC:Complex/A:None/CI:All/II:All/E:Theoretical/TD:UncommonVulnerability: Arbitrary PHP code executionCVE IDs: CVE-2020-13664Description: Drupal 8 and 9 have a remote code execution vulnerability under certain circumstances.An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker could More info: https://www.drupal.org/sa-core-2020-005 |
|














