Improper sanitization in the extension file names is present in Drupal core.
PoC: CVE-2020-13671
CVE-2020-13671 - Drupal RCE via File Upload Vulnerability Analysis and PoC
PoC: CVE-2020-13671-old
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.