Umbraco.Cms is vulnerable to Unrestricted Upload of File with Dangerous Type
55
Medium Risk
Affected versions of this package are vulnerable to Arbitrary File Upload due to insufficient validation of file extensions in API requests. An attacker can craft a request that bypasses the configured restrictions, allowing the upload of files with disallowed or dangerous extensions.
You are affected if you are using a version that falls within the vulnerable range.
Umbraco.Cms is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 14.0.0 - 15.4.1.
Upgrade the Umbraco.Cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant