CVE-2023-49279
Last modified
CVE-2023-49279 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Umbraco is an ASP.NET content management system (CMS). Starting in version 7.0.0 and prior to versions 7.15.11, 8.18.9, 10.7.0, 11.5.0, and 12.2.0, a user with access to the backoffice can upload SVG files that include scripts. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
Umbraco is an ASP.NET content management system (CMS). Starting in version 7.0.0 and prior to versions 7.15.11, 8.18.9, 10.7.0, 11.5.0, and 12.2.0, a user with access to the backoffice can upload SVG files that include scripts. If the user can trick another user to load the media directly in a browser, the scripts can be executed. Versions 7.15.11, 8.18.9, 10.7.0, 11.5.0, and 12.2.0 contain a patch for this issue. Some workarounds are available. Implement the server side file validation or serve all media from an different host (e.g cdn) than where Umbraco is hosted.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Umbraco | Umbraco Cms | >= 7.0.0, < 7.15.11 |
| Umbraco | Umbraco Cms | >= 8.0.0, < 8.18.9 |
| Umbraco | Umbraco Cms | >= 10.0.0, < 10.7.0 |
| Umbraco | Umbraco Cms | >= 11.0.0, < 11.5.0 |
| Umbraco | Umbraco Cms | >= 12.0.0, < 12.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-49279?
How severe is CVE-2023-49279?
How do I fix CVE-2023-49279?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-49273Umbraco is an ASP.NET content management system (CMS). Start…5.4
- CVE-2023-49274Umbraco is an ASP.NET content management system (CMS). Start…5.3
- CVE-2023-49275Wazuh is a free and open source platform used for threat pre…6.5
- CVE-2023-49276Uptime Kuma is an open source self-hosted monitoring tool. I…6.1
- CVE-2023-49277dpaste is an open source pastebin application written in Pyt…6.1
- CVE-2023-49278Umbraco is an ASP.NET content management system (CMS). Start…5.3
- CVE-2023-4928 SQL Injection in GitHub repository instantsoft/icms2 prior …7.2
- CVE-2023-49280XWiki Change Request is an XWiki application allowing to req…6.5
- CVE-2023-49281Calendarinho is an open source calendaring application to ma…6.1
- CVE-2023-49282msgraph-sdk-php is the Microsoft Graph Library for PHP. The …5.3
- CVE-2023-49283microsoft-graph-core the Microsoft Graph Library for PHP. Th…5.3
- CVE-2023-49284fish is a smart and user-friendly command line shell for mac…6.6
Are you affected by CVE-2023-49279?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
