Low severityNVD Advisory· Published Oct 22, 2024· Updated Oct 22, 2024
Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API
CVE-2024-48925
Description
Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0. The issue allows low-privilege users to access the webhook API and retrieve information that should be restricted to users with access to the settings section. Version 14.3.0 contains a patch.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Umbraco.CMSNuGet | >= 14.0.0, < 14.3.0 | 14.3.0 |
Affected products
1- Range: >= 14.0.0, < 14.3.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-4gp9-ff99-j6vjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-48925ghsaADVISORY
- github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-4gp9-ff99-j6vjghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.