6.5
CVSSv3

CVE-2020-5811

Published: 30/12/2020 Updated: 18/10/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

umbraco umbraco cms

Exploits

Umbraco CMS versions 891 and below suffer from path traversal and arbitrary file write vulnerabilities ...