CVE-2021-37334

CRITICALCVSS 9.8/10EPSS 2.74%

Last modified

CVE-2021-37334 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Umbraco Forms version 4.0.0 up to and including 8.7.5 and below are vulnerable to a security flaw that could lead to a remote code execution attack and/or arbitrary file deletion. A vulnerability occurs because validation of the file extension is performed after the file has been stored in a temporary directory. EPSS estimates a 2.74% chance of exploitation in the next 30 days.

Description

Umbraco Forms version 4.0.0 up to and including 8.7.5 and below are vulnerable to a security flaw that could lead to a remote code execution attack and/or arbitrary file deletion. A vulnerability occurs because validation of the file extension is performed after the file has been stored in a temporary directory. By default, files are stored within the application directory structure at %BASEDIR%/APP_DATA/TEMP/FileUploads/. Whilst access to this directory is restricted by the root web.config file, it is possible to override this restriction by uploading another specially crafted web.config file to the temporary directory. It is possible to exploit this flaw to upload a malicious script file to execute arbitrary code and system commands on the server.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
2.74%

84.3th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
UmbracoForms>= 4.0.0, < 4.4.9
UmbracoForms>= 6.0.0, < 6.0.10
UmbracoForms>= 7.0.0, < 7.0.7
UmbracoForms>= 7.1.0, < 7.1.4
UmbracoForms>= 7.2.0, < 7.2.1
UmbracoForms>= 7.3.0, < 7.3.2
UmbracoForms>= 7.4.0, < 7.4.3
UmbracoForms>= 7.5.0, < 7.5.4
UmbracoForms>= 8.0.0, < 8.0.2
UmbracoForms>= 8.1.0, < 8.1.6
UmbracoForms>= 8.2.0, < 8.2.3
UmbracoForms>= 8.3.0, < 8.3.4
UmbracoForms>= 8.4.0, < 8.4.4
UmbracoForms>= 8.5.0, < 8.5.7
UmbracoForms>= 8.6.0, < 8.6.2
UmbracoForms>= 8.7.0, < 8.7.6

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-37334?
Umbraco Forms version 4.0.0 up to and including 8.7.5 and below are vulnerable to a security flaw that could lead to a remote code execution attack and/or arbitrary file deletion. A vulnerability occurs because validation of the file extension is performed after the file has been stored in a temporary directory. By default, files are stored within the application directory structure at %BASEDIR%/APP_DATA/TEMP/FileUploads/. Whilst access to this directory is restricted by the root web.config file, it is possible to override this restriction by uploading another specially crafted web.config file to the temporary directory. It is possible to exploit this flaw to upload a malicious script file to execute arbitrary code and system commands on the server.
How severe is CVE-2021-37334?
CVE-2021-37334 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 2.74% probability of exploitation in the next 30 days.
How do I fix CVE-2021-37334?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-37334?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST