HIGH 7.5 NuGet
Insecure defaults in UmbracoForms
GHSA-8m73-w2r2-6xxj · CVE-2020-7685
Published · Modified
Description
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes