Authenticated path traversal in Umbraco CMS
Moderate severity
GitHub Reviewed
Published
Apr 13, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Dec 30, 2020
Reviewed
Apr 6, 2021
Published to the GitHub Advisory Database
Apr 13, 2021
Last updated
Feb 1, 2023
An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.
References