Drupal: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Dienstes — WID-SEC-2024-1938
BSI · WID-SEC-2024-1938
ID
WID-SEC-2024-1938
WID-SEC-2024-1938
Date
Updated
Source
BSI
BSI
Threat
high
high
Summary
Drupal ist ein freies Content-Management-System, basierend auf der Scriptsprache PHP und einer SQL-Datenbank. Über zahlreiche Extensions kann der Funktionsumfang der Core-Installation individuell erweitert werden.
Timeline
- Published by source
- 2020-11-19
- Last source activity
- 2026-08-24
- Time from publication to latest source activity
- 2104 days
Risk context
- Reported severity or threat level: high.
What to do
General, cautious steps (verify details in the official source):
- Prioritize patching or mitigation immediately (treat as actively risky).
- Identify affected product versions in your inventory and verify whether you are impacted.
- Apply vendor patches/updates or recommended mitigations as soon as available.
- Read the official advisory for exact affected versions and remediation steps.
Official advisory
Evidence and provenance
- Canonical advisory ID
- WID-SEC-2024-1938
- Source
- BSI
- Published by source
- 2020-11-19
- Last source activity
- 2026-08-24
- Additional identifiers
- CVE-2020-13671
- Curated by
- hlukh.ch
Related advisories and connections
These advisories are connected by shared CVE, product, vendor, source, or time signals.