-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| drupal/core | composer | >= 8.0.0, < 8.7.11 | 8.7.11 |
| drupal/core | composer | >= 8.8.0, < 8.8.1 | 8.8.1 |
The vulnerability description explicitly identifies file_save_upload() as the problematic function that lacked filename sanitization present in Drupal 7. The security advisory and patch notes specifically mention this function's behavior modification (adding trim operations) as the fix. No other functions are mentioned in the context of this filename sanitization vulnerability.
Ongoing coverage of React2Shell