File Upload Vulnerability in SilverStripe CMS by SilverStripe
CVE-2020-9280
7.5HIGH
What is CVE-2020-9280?
In SilverStripe versions through 4.5, a vulnerability exists where files that are uploaded via Forms could be inadvertently stored in the default '/Uploads' directory. This issue specifically impacts installations that previously utilized the silverstripe/secureassets module for folder protection within versions 3.x. If the module was enabled during the upgrade to 4.x, any subsequent file uploads bypass this protection, creating a potential risk of unauthorized access to sensitive files. It is essential for users to assess their upgrade paths and implement appropriate security measures to mitigate this risk.
