Saturday, 22 February
poster

Friday, 24 March2023

Drupal fixes critical bug allowing hackers to access websites

Drupal fixes critical bug allowing hackers to access websites

<p>CMS platform Drupal has released security updates to patch the critical vulnerability called CVE-2020-13671. The vulnerability was easy to exploit and relied on &quot;double extension&quot; trick. The said vulnerability didn&#39;t allow CMS to sanitise &quot;certain&quot; file names, letting malicious files to slip in. The situation could lead to &quot;files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations&quot;.</p>

Read full story at Infotech Lead
Tags:

Subscribe To Our Newsletter.

Full Name
Email