Path traversal in Umbraco CMS - CVE-2023-49089
Published: December 13, 2023
Umbraco CMS
Umbraco
Description
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the backoffice component. A remote user with permissions to create packages can send a specially crafted HTTP request and write arbitrary files outside of the expected location.