PT-2020-20683 · Umbraco · Umbraco Cloud

Published

2020-03-16

·

Updated

2022-05-24

·

CVE-2020-9471

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Umbraco Cloud version 8.5.3
Description The issue allows an authenticated file upload, which can lead to Remote Code Execution, via the Install Packages functionality.
Recommendations For Umbraco Cloud version 8.5.3, update to a version that fixes this issue to prevent authenticated file upload and potential Remote Code Execution.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9471
GHSA-H68C-4JH3-CP9J

Affected Products

Umbraco Cloud