Medium severity4.3NVD Advisory· Published Jan 23, 2020· Updated Jun 17, 2026
CVE-2020-7210
CVE-2020-7210
Description
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
UmbracoCMS.CoreNuGet | < 8.5.0 | 8.5.0 |
Affected products
3- cpe:2.3:a:umbraco:umbraco_cms:8.2.2:*:*:*:*:*:*:*
- Umbraco/CMSdescription
Patches
Vulnerability mechanics
References
8- packetstormsecurity.com/files/156062/Umbraco-CMS-8.2.2-Cross-Site-Request-Forgery.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- seclists.org/fulldisclosure/2020/Jan/33nvdExploitMailing ListThird Party AdvisoryWEB
- sec-consult.com/en/blog/advisories/cross-site-request-forgery-csrf-in-umbraco-cms/nvdExploitThird Party Advisory
- seclists.org/bugtraq/2020/Jan/35nvdExploitMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-gqqf-8cx6-9r7hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7210ghsaADVISORY
- sec-consult.com/en/vulnerability-lab/advisories/index.htmlnvdThird Party Advisory
- sec-consult.com/en/blog/advisories/cross-site-request-forgery-csrf-in-umbraco-cmsghsaWEB
News mentions
0No linked articles in our index yet.