Umbraco是丹麦Umbraco公司的一套C#编写的开源的内容管理系统(CMS)。 Umbraco 14.0.0及之前版本存在跨站脚本漏洞,该漏洞源于容易受到跨站脚本攻击,可能被利用来访问更高权限的端点。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| umbraco | Umbraco-CMS | >= 14.0.0, < 14.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-48927 | 4.6 MEDIUM | Potential Code Execution Risk When Viewing SVG Files in Full Screen in Backoffice |
| CVE-2024-48929 | 4.2 MEDIUM | Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out |
| CVE-2024-48926 | 4.2 MEDIUM | Umbraco CMS logout page displayed before session expiration |
| CVE-2024-48925 | Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Web |
No comments yet