← Back to CVE List

CVE-2020-9280

Published: 2020-04-15T21:15Z
Last Modified: 2024-11-21T05:40Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x. This module is installed and enabled by default on the Common Web Platform (CWP). The vulnerability only affects files uploaded after an upgrade to 4.x. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt