Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.6 NuGet

Umbraco has a Potential Code Execution Risk When Viewing SVG Files in Full Screen in Backoffice

GHSA-5955-cwv4-h7qh · CVE-2024-48927

Published · Modified

Description

Impact

There is a potential risk of code execution for Backoffice users when they “preview” SVG files in full screen mode.

Workarounds

Server-side file validation is available to strip script tags from file's content during the file upload process.

Ready to move

Start Securing

Free, no credit card | First findings in minutes