Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.18.15. There is a potential risk of code execution for Backoffice users when they “preview” SVG files in full screen mode. Versions 13.5.2, 10.8,7, and 8.18.15 contain a patch for the issue. As a workaround, derver-side file validation is available to strip script tags from file's content during the file upload process.
History

Fri, 25 Oct 2024 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Tue, 22 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Umbraco
Umbraco umbraco Cms
CPEs cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*
Vendors & Products Umbraco
Umbraco umbraco Cms
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Oct 2024 16:00:00 +0000

Type Values Removed Values Added
Description Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.18.15. There is a potential risk of code execution for Backoffice users when they “preview” SVG files in full screen mode. Versions 13.5.2, 10.8,7, and 8.18.15 contain a patch for the issue. As a workaround, derver-side file validation is available to strip script tags from file's content during the file upload process.
Title Potential Code Execution Risk When Viewing SVG Files in Full Screen in Backoffice
Weaknesses CWE-74
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-22T15:50:46.892Z

Updated: 2024-10-22T16:07:12.486Z

Reserved: 2024-10-09T22:06:46.174Z

Link: CVE-2024-48927

cve-icon Vulnrichment

Updated: 2024-10-22T16:06:59.734Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-22T16:15:08.360

Modified: 2024-10-25T16:15:13.327

Link: CVE-2024-48927

cve-icon Redhat

No data.