Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 NuGet

Authenticated path traversal in Umbraco CMS

GHSA-936x-wgqv-hhgq · CVE-2020-5811

Published · Modified

Description

An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.

Ready to move

Start Securing

Free, no credit card | First findings in minutes