Dangerous file upload in Umbraco CMS - CVE-2024-48927

 

Dangerous file upload in Umbraco CMS - CVE-2024-48927

Published: October 22, 2024 / Updated: October 23, 2024


Vulnerability identifier: #VU99234
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2024-48927
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform XSS attacks.

The vulnerability exists due to the application allows to upload SVG files to the server. A remote user can upload a specially crafted SVG file with an arbitrary JavaScript code inside and execute ti in the victim's browser in the security context of the website once the image is viewed.


Affected software

Umbraco CMS

How to mitigate CVE-2024-48927

Install updates from vendor's website.

Umbraco CMS - addressed in versions 8.18.15, 10.8.7, 13.5.2

External References

Related Security Bulletins