#VU34732 Arbitrary file upload in Umbraco CMS - CVE-2020-9472

 

#VU34732 Arbitrary file upload in Umbraco CMS - CVE-2020-9472

Published: March 16, 2020 / Updated: April 18, 2021


Vulnerability identifier: #VU34732
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2020-9472
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
Umbraco CMS
Software vendor:
Umbraco

Description

The vulnerability allows a remote authenticated user to manipulate data.

Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.


Remediation

Install update from vendor's website.

External links