- Description
- Umbraco is an ASP.NET content management system (CMS). Starting in version 7.0.0 and prior to versions 7.15.11, 8.18.9, 10.7.0, 11.5.0, and 12.2.0, a user with access to the backoffice can upload SVG files that include scripts. If the user can trick another user to load the media directly in a browser, the scripts can be executed. Versions 7.15.11, 8.18.9, 10.7.0, 11.5.0, and 12.2.0 contain a patch for this issue. Some workarounds are available. Implement the server side file validation or serve all media from an different host (e.g cdn) than where Umbraco is hosted.
- Source
- security-advisories@github.com
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 5.4
- Impact score
- 2.7
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- security-advisories@github.com
- CWE-79
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F339F5B2-A184-4105-8BC9-D3FD1B793271",
"versionEndExcluding": "7.15.11",
"versionStartIncluding": "7.0.0"
},
{
"criteria": "cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "185C2350-DA24-42EE-885E-39DAACBFB294",
"versionEndExcluding": "8.18.9",
"versionStartIncluding": "8.0.0"
},
{
"criteria": "cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE39433E-172C-42F4-BD74-31FA96A8FF05",
"versionEndExcluding": "10.7.0",
"versionStartIncluding": "10.0.0"
},
{
"criteria": "cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7E68D9FA-67C8-456C-926E-36E76A7B77B9",
"versionEndExcluding": "11.5.0",
"versionStartIncluding": "11.0.0"
},
{
"criteria": "cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6842FACF-64C1-40A1-9B7A-ADF855867C3C",
"versionEndExcluding": "12.2.0",
"versionStartIncluding": "12.0.0"
}
],
"operator": "OR"
}
]
}
]