Umbraco是丹麦Umbraco公司的一套C#编写的开源的内容管理系统(CMS)。 Umbraco 存在跨站脚本漏洞,该漏洞源于有权访问后台的用户可以上传包含脚本的 SVG 文件。 如果用户可以欺骗其他用户直接在浏览器中加载媒体,则可以执行脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| umbraco | Umbraco-CMS | >= 7.0.0, < 7.15.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-49089 | 7.7 HIGH | Umbraco CMS possible path traversal when creating packages from backoffice |
| CVE-2023-49273 | 5.4 MEDIUM | Umbraco CMS vulnerable to Privilege Escalation using Spoofing |
| CVE-2023-49278 | 5.3 MEDIUM | Umbraco CMS brute force exploit can be used to collect valid usernames |
| CVE-2023-48227 | 4.3 MEDIUM | Umbraco CMS Backoffice User can bypass "Publish" restriction |
| CVE-2023-48313 | 4.3 MEDIUM | Umbraco contains a DOM-XSS |
| CVE-2023-49274 | 3.7 LOW | Umbraco CMS SMTP misconfiguration exposes potential registered user email |
| CVE-2023-38694 | 3.5 LOW | Umbraco CMS vulnerable to possible injection of HTML in an unintended form |
No comments yet