Umbraco CMS is prone to a vulnerability that lets attackers upload arbitrary files because it fails to properly authorize users before allowing them to perform certain actions.
An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.Umbraco CMS 4.7.0.378 is vulnerable; other versions may also be affected.
Vendor Status:
Currently we are not aware of any vendor-supplied patches