Vulnerabilities
Vulnerable Software
Umbraco:  >> Umbraco Forms  >> 4.3.1  Security Vulnerabilities
Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short and long answer fields are validated only client-side, not server-side. This issue has been patched in versions 8.13.16, 10.5.7, 13.2.2, and 14.1.2. Users are advised to upgrade. There are no known workarounds for this issue.
CVSS Score
5.8
EPSS Score
0.001
Published
2025-01-14
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend validation that blocks certain file types, depending on their security needs and policies.
CVSS Score
5.4
EPSS Score
0.004
Published
2020-07-28


Contact Us

Shodan ® - All rights reserved