CVE-2020-5810: XSS
Published Dec 30, 2020
·Updated
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload.
Affected Software
1 affected component
Umbraco Umbraco CMS<=8.9.1
Event History
Dec 30, 2020
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-5810.
2
What is the title of this vulnerability?
The title of this vulnerability is 'A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current'.
3
What is the description of this vulnerability?
The description of this vulnerability is 'A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload.'
4
What is the affected software version?
The affected software version is Umbraco CMS <= 8.9.1 or current.
5
What is the severity of this vulnerability?
The severity of this vulnerability is medium, with a CVSS score of 5.4.