vendor:
Umbraco CMS
by:
BitTheByte
6,5
CVSS
MEDIUM
Path Traversal and Arbitrary File Write
22
CWE
Product Name: Umbraco CMS
Affected Version From: <= 8.9.1
Affected Version To: None
Patch Exists: YES
Related CWE: CVE-2020-5811
CPE: a:umbraco:umbraco_cms
Metasploit:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2020
Umbraco CMS 8.9.1 – Path traversal and Arbitrary File Write (Authenticated)
Authenticated path traversal vulnerability which allows an attacker to write arbitrary files on the target server.
Mitigation:
Upgrade to the latest version of Umbraco CMS 8.9.2 or later.