CVE-2020-9471: Malicious File Upload
Published Mar 16, 2020
·Updated
Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.
Affected Software
1 affected component
Umbraco Umbraco CMS=8.5.3
Event History
Mar 16, 2020
CVE Published
via MITRE·07:44 PM
Data Sourced
via MITRE·07:44 PM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-9471?
CVE-2020-9471 is a vulnerability in Umbraco Cloud 8.5.3 that allows an authenticated file upload and remote code execution.
2
How severe is CVE-2020-9471?
CVE-2020-9471 is classified as a high severity vulnerability with a severity score of 8.8.
3
How does CVE-2020-9471 work?
CVE-2020-9471 allows an authenticated user to upload a file through the Install Packages functionality, which can lead to remote code execution.
4
How can I fix CVE-2020-9471?
To fix CVE-2020-9471, it is recommended to update Umbraco Cloud to a version that is not affected by the vulnerability.
5
Is there a reference for CVE-2020-9471?
Yes, you can find more information about CVE-2020-9471 at the following link: https://gitlab.com/eLeN3Re/cve-2020-9471