Umbraco has a Potential Code Execution Risk When Viewing SVG Files in Full Screen in Backoffice
Moderate severity
GitHub Reviewed
Published
Oct 22, 2024
in
umbraco/Umbraco-CMS
•
Updated Oct 22, 2024
Description
Published by the National Vulnerability Database
Oct 22, 2024
Published to the GitHub Advisory Database
Oct 22, 2024
Reviewed
Oct 22, 2024
Last updated
Oct 22, 2024
Impact
There is a potential risk of code execution for Backoffice users when they “preview” SVG files in full screen mode.
Workarounds
Server-side file validation is available to strip script tags from file's content during the file upload process.
References