Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8m73-w2r2-6xxj

Опубликовано: 29 июл. 2020
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Insecure defaults in UmbracoForms

This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies.

Пакеты

Наименование

UmbracoForms

nuget
Затронутые версииВерсия исправления

<= 8.4.1

Отсутствует

EPSS

Процентиль: 63%
0.00449
Низкий

7.5 High

CVSS3

Дефекты

CWE-1188

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies.

EPSS

Процентиль: 63%
0.00449
Низкий

7.5 High

CVSS3

Дефекты

CWE-1188