Description
Umbraco CMS version 4.7.0 is vulnerable to a remote code execution vulnerability. An attacker can upload files via an unsecured web service located at /umbraco/webservices/codeEditorSave.asmx (method SaveDLRScript). Acunetix created a file named testAcunetix.test to test for this vulnerability.
Remediation
Upgrade to the latest version of Umbraco CMS.
References
Related Vulnerabilities
SharePoint Interpretation Conflict Vulnerability (CVE-2021-28474)
Apache Tomcat Other Vulnerability (CVE-2003-0045)
Jboss EAP Improper Input Validation Vulnerability (CVE-2020-1757)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-1454)
Moodle Uncontrolled Recursion Vulnerability (CVE-2021-36395)