Umbraco UmbracoForms
cpe:2.3:a:umbraco:umbraco_forms:*:*:*:*:*:*:*, +1 more
- <= 8.13.16
A remote code execution vulnerability exists in Umbraco UmbracoForms versions through 8.13.16. An authenticated attacker can exploit this issue by providing a malicious WSDL (Web Service Description Language) URL as a data source, which is then processed by the application, leading to unauthorized code execution.
Exploitation of this vulnerability allows for remote code execution on the server where Umbraco Forms is installed.
Users are advised to upgrade to Umbraco Forms version 13.0.0 or later. Instructions for upgrading can be found in the Umbraco Forms documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.