QID 980734
QID 980734: Dotnet (nuget) Security Update for UmbracoForms (GHSA-8m73-w2r2-6xxj)
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8m73-w2r2-6xxj for updates pertaining to this vulnerability.
Vendor References
- GHSA-8m73-w2r2-6xxj -
github.com/advisories/GHSA-8m73-w2r2-6xxj
CVEs related to QID 980734
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8m73-w2r2-6xxj | UmbracoForms |
|