Description
Umbraco CMS version 4.7.0 is vulnerable to a remote code execution vulnerability. An attacker can upload files via an unsecured web service located at /umbraco/webservices/codeEditorSave.asmx (method SaveDLRScript). Acunetix created a file named testAcunetix.test to test for this vulnerability.
Remediation
Upgrade to the latest version of Umbraco CMS.
References
Related Vulnerabilities
Django Uncontrolled Resource Consumption Vulnerability (CVE-2021-45115)
Perl Improper Input Validation Vulnerability (CVE-2016-2381)
MySQL Other Vulnerability (CVE-2010-3682)
Django Uncontrolled Resource Consumption Vulnerability (CVE-2023-24580)
Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2022-26595)