CVE-2014-10074

CRITICAL

Umbraco Cms < 7.2.0 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not block the upload of .php files.

References (2)

Core 2
Core References
Exploit, Vendor Advisory x_refsource_misc
http://issues.umbraco.org/issue/U4-5901

Scores

CVSS v3 9.8
EPSS 0.0133
EPSS Percentile 80.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
umbraco/umbraco_cms < 7.2.0
Published Aug 27, 2018
Tracked Since Feb 18, 2026