First published: Mon Mar 16 2020(Updated: )
Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Umbraco CMS | =8.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9471 is a vulnerability in Umbraco Cloud 8.5.3 that allows an authenticated file upload and remote code execution.
CVE-2020-9471 is classified as a high severity vulnerability with a severity score of 8.8.
CVE-2020-9471 allows an authenticated user to upload a file through the Install Packages functionality, which can lead to remote code execution.
To fix CVE-2020-9471, it is recommended to update Umbraco Cloud to a version that is not affected by the vulnerability.
Yes, you can find more information about CVE-2020-9471 at the following link: https://gitlab.com/eLeN3Re/cve-2020-9471