Backoffice users with permissions to create packages can use path traversal and thereby write outside of the expected location.
The “Package” section in Umbraco Backoffice allows a logged in user to write folders outside of the default package directory.
{ "nvd_published_at": "2023-12-12T19:15:07Z", "cwe_ids": [ "CWE-22" ], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2023-12-13T13:24:53Z" }