Description
Umbraco CMS version 4.7.0 is vulnerable to a remote code execution vulnerability. An attacker can upload files via an unsecured web service located at /umbraco/webservices/codeEditorSave.asmx (method SaveDLRScript). Acunetix created a file named testAcunetix.test to test for this vulnerability.
Remediation
Upgrade to the latest version of Umbraco CMS.
References
Related Vulnerabilities
Oracle Application Server Resource Management Errors Vulnerability (CVE-2007-2120)
Python Improper Input Validation Vulnerability (CVE-2021-29921)
Zope Web Application Server Resource Management Errors Vulnerability (CVE-2008-5102)
MySQL CVE-2020-14793 Vulnerability (CVE-2020-14793)
Oracle Application Server Other Vulnerability (CVE-2000-1236)