CVE-2020-5811: Path Traversal
Published Dec 30, 2020
·Updated
An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.
Affected Software
1 affected component
Umbraco Umbraco CMS<=8.9.1
Event History
Dec 30, 2020
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Umbraco CMS vulnerability?
The vulnerability ID for this Umbraco CMS vulnerability is CVE-2020-5811.
2
What is the severity of CVE-2020-5811?
CVE-2020-5811 has a severity rating of 6.5 (Medium).
3
What is the description of CVE-2020-5811?
CVE-2020-5811 is an authenticated path traversal vulnerability that exists during package installation in Umbraco CMS <= 8.9.1 or current, allowing arbitrary files to be written outside of the site home and expected paths.
4
Which software is affected by CVE-2020-5811?
CVE-2020-5811 affects Umbraco CMS version <= 8.9.1 or current.
5
How can I fix CVE-2020-5811 in Umbraco CMS?
To fix CVE-2020-5811 in Umbraco CMS, update to a version that is newer than 8.9.1.