Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-5811. PoCs published by BitTheByte.
AI-analyzed exploit summary This exploit leverages an authenticated path traversal vulnerability in Umbraco CMS to create a malicious package that can write arbitrary files to the server. It generates a ZIP file containing a shell payload and a crafted XML manifest to facilitate the attack.
Description
An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.
Exploits (1)
This exploit leverages an authenticated path traversal vulnerability in Umbraco CMS to create a malicious package that can write arbitrary files to the server. It generates a ZIP file containing a shell payload and a crafted XML manifest to facilitate the attack.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N