Drupal officially released a security notice stating that it has fixed a high-risk remote code execution vulnerability (CVE-2019-6340). The vulnerability stems from the fact that certain fields are not properly filtered when input through non-form resources, resulting in potentially arbitrary PHP code execution. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021. Other reference:None