CVE-2020-7685
Last modified
CVE-2020-7685 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. EPSS estimates a 0.90% chance of exploitation in the next 30 days.
Description
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Umbraco | Umbraco Forms | All versions |
References
- https://snyk.io/vuln/SNYK-DOTNET-UMBRACOFORMS-595765Third Party Advisory
- https://snyk.io/vuln/SNYK-DOTNET-UMBRACOFORMS-595765Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-7685?
How severe is CVE-2020-7685?
How do I fix CVE-2020-7685?
Are you affected by CVE-2020-7685?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
