vendor:
Umbraco CMS
by:
Gregory DRAPERI & Hugo BOUTINON
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Umbraco CMS
Affected Version From: 7.12.4
Affected Version To: 7.12.4
Patch Exists: YES
Related CWE: N/A
CPE: a:umbraco:umbraco_cms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows IIS
2019
Umbraco CMS – Remote Code Execution by authenticated administrators
A vulnerability in Umbraco CMS allows authenticated administrators to execute arbitrary code on the server. This is achieved by sending a specially crafted payload to the vulnerable web page. The payload is an XSLT stylesheet containing a C# script that executes the calc.exe program. The vulnerable web page is located at /umbraco/developer/Xslt/xsltVisualize.aspx.
Mitigation:
Upgrade to the latest version of Umbraco CMS.