CVE-2020-7685
When using the default configuration for upload forms, it is possible to upload arbitrary file types.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.90%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.90% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1188
- Affected
- umbraco/umbraco forms
- Source
- report@snyk.io
References
- https://snyk.io/vuln/SNYK-DOTNET-UMBRACOFORMS-595765Third Party Advisory
- https://snyk.io/vuln/SNYK-DOTNET-UMBRACOFORMS-595765Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.