PT-2020-20684 · Umbraco · Umbraco Cms+1

Published

2020-03-16

·

Updated

2022-05-24

·

CVE-2020-9472

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Umbraco CMS version 8.5.3 Umbraco Cloud version 8.5.3
Description The issue allows an authenticated file upload, which can lead to Remote Code Execution, via the Install Package or Install Packages functionality.
Recommendations For Umbraco CMS version 8.5.3, consider disabling the Install Package functionality until a patch is available. For Umbraco Cloud version 8.5.3, restrict access to the Install Packages functionality to minimize the risk of exploitation.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9472
GHSA-H68C-4JH3-CP9J
GHSA-J66F-H9HM-975M

Affected Products

Umbraco Cms
Umbraco Cloud