First published: Wed Dec 30 2020(Updated: )
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Umbraco CMS | <=8.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2020-5810.
The title of this vulnerability is 'A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current'.
The description of this vulnerability is 'A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload.'
The affected software version is Umbraco CMS <= 8.9.1 or current.
The severity of this vulnerability is medium, with a CVSS score of 5.4.