Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-49279
HistoryDec 12, 2023 - 8:15 p.m.

Input validation

2023-12-1220:15:00
PRIOn knowledge base
www.prio-n.com
3
umbraco cms
svg files
malicious upload
version vulnerability
server side validation
media hosting

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

13.3%

Umbraco is an ASP.NET content management system (CMS). Starting in version 7.0.0 and prior to versions 7.15.11, 8.18.9, 10.7.0, 11.5.0, and 12.2.0, a user with access to the backoffice can upload SVG files that include scripts. If the user can trick another user to load the media directly in a browser, the scripts can be executed. Versions 7.15.11, 8.18.9, 10.7.0, 11.5.0, and 12.2.0 contain a patch for this issue. Some workarounds are available. Implement the server side file validation or serve all media from an different host (e.g cdn) than where Umbraco is hosted.

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

13.3%

Related for PRION:CVE-2023-49279