CVE-2020-5810
MEDIUM WAF: High
CVSS 5.4
Published: 2020-12-30
CWE-79
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload.
WAF Coverage Analysis
Cross-Site Scripting (XSS)
High WAF Coverage
OWASP: A03:2021 Injection
941xxx - XSS / XXE
Affected Software
| Vendor | Product | Version |
|---|---|---|
| umbraco | umbraco_cms | up to 8.9.1 |
References
- www.tenable.com (Exploit, Third Party Advisory)