Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c8gg-qc8v-6jfx

Опубликовано: 13 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the fileName parameter, attackers can write malicious ASPX scripts directly into the web-accessible /umbraco/ directory and execute them remotely.

Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the fileName parameter, attackers can write malicious ASPX scripts directly into the web-accessible /umbraco/ directory and execute them remotely.

EPSS

Процентиль: 99%
0.75944
Высокий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
6 месяцев назад

Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the fileName parameter, attackers can write malicious ASPX scripts directly into the web-accessible /umbraco/ directory and execute them remotely.

EPSS

Процентиль: 99%
0.75944
Высокий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-434