An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-0802 An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.
Github GHSA Github GHSA GHSA-936x-wgqv-hhgq Authenticated path traversal in Umbraco CMS
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2024-08-04T08:39:25.926Z

Reserved: 2020-01-06T00:00:00

Link: CVE-2020-5811

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-30T16:15:12.447

Modified: 2024-11-21T05:34:38.443

Link: CVE-2020-5811

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses