Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.0, Backoffice users with permissions to create packages can use path traversal and thereby write outside of the expected location. Versions 8.18.10, 10.8.1, and 12.3.0 contain a patch for this issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3121 | Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.0, Backoffice users with permissions to create packages can use path traversal and thereby write outside of the expected location. Versions 8.18.10, 10.8.1, and 12.3.0 contain a patch for this issue. |
Github GHSA |
GHSA-6324-52pr-h4p5 | Using the directory back payload (“/../”) in a package name allows placement of package in other folders. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T21:46:29.033Z
Reserved: 2023-11-21T18:57:30.429Z
Link: CVE-2023-49089
No data.
Status : Modified
Published: 2023-12-12T19:15:07.840
Modified: 2024-11-21T08:32:47.960
Link: CVE-2023-49089
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA