Launch Week Day 1: Announcing Security Design Review
NONE 0.0 NuGet

Using the directory back payload (“/../”) in a package name allows placement of package in other folders.

GHSA-6324-52pr-h4p5 · CVE-2023-49089

Published · Modified

Description

Impact

Backoffice users with permissions to create packages can use path traversal and thereby write outside of the expected location.

Explanation of the vulnerability

The “Package” section in Umbraco Backoffice allows a logged in user to write folders outside of the default package directory.

Ready to move

Start Securing

Free, no credit card | First findings in minutes