Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-936x-wgqv-hhgq

Опубликовано: 13 апр. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Authenticated path traversal in Umbraco CMS

An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.

Пакеты

Наименование

UmbracoCms

nuget
Затронутые версииВерсия исправления

< 8.9.2

8.9.2

EPSS

Процентиль: 85%
0.02606
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
nvd
около 5 лет назад

An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.

EPSS

Процентиль: 85%
0.02606
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22