CVE-2023-49089

HIGH

Umbraco <8.18.10-12.3.0 - Path Traversal

Title source: llm
STIX 2.1

Description

Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.0, Backoffice users with permissions to create packages can use path traversal and thereby write outside of the expected location. Versions 8.18.10, 10.8.1, and 12.3.0 contain a patch for this issue.

References (1)

Core 1
Core References

Scores

CVSS v3 7.7
EPSS 0.0012
EPSS Percentile 30.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Details

CWE
CWE-22
Status published
Products (2)
nuget/Umbraco.CMS 8.0.0 - 8.18.10NuGet
umbraco/umbraco_cms 8.0.0 - 8.18.10
Published Dec 12, 2023
Tracked Since Feb 18, 2026