MEDIUM 6.5 NuGet
Authenticated path traversal in Umbraco CMS
GHSA-936x-wgqv-hhgq · CVE-2020-5811
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.
Ready to move
Start Securing
Free, no credit card | First findings in minutes