We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-48925

Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API



Description

Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0. The issue allows low-privilege users to access the webhook API and retrieve information that should be restricted to users with access to the settings section. Version 14.3.0 contains a patch.

Reserved 2024-10-09 | Published 2024-10-22 | Updated 2024-10-22 | Assigner GitHub_M

Problem types

CWE-284: Improper Access Control

CWE-863: Incorrect Authorization

Product status

>= 14.0.0, < 14.3.0
affected

References

github.com/...co-CMS/security/advisories/GHSA-4gp9-ff99-j6vj

cve.org (CVE-2024-48925)

nvd.nist.gov (CVE-2024-48925)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-48925

Support options

Helpdesk Chat, Email, Knowledgebase