Medium severity6.5NVD Advisory· Published Dec 30, 2020· Updated Jun 17, 2026
CVE-2020-5811
CVE-2020-5811
Description
An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
UmbracoCmsNuGet | < 8.9.2 | 8.9.2 |
Affected products
3- Umbraco/Umbraco CMSdescription
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/163965/Umbraco-CMS-8.9.1-Traversal-Arbitrary-File-Write.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- www.tenable.com/security/research/tra-2020-59nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-936x-wgqv-hhgqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-5811ghsaADVISORY
News mentions
0No linked articles in our index yet.