CVE-2020-5811
MEDIUMUmbraco CMS <=8.9.1 - Path Traversal
Title source: llmDescription
An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.
Exploits (1)
Scores
CVSS v3
6.5
EPSS
0.0261
EPSS Percentile
85.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-22
Status
published
Products (2)
nuget/UmbracoCms
0 - 8.9.2NuGet
umbraco/umbraco_cms
< 8.9.1
Published
Dec 30, 2020
Tracked Since
Feb 18, 2026