Umbraco CMS是丹麦Umbraco公司的一个内容管理系统。 Umbraco CMS 14.0.0版本至14.3.0之前版本存在安全漏洞,该漏洞源于存在访问控制不当问题,允许低权限用户访问webhook API并检索应仅限于有权访问设置部分的用户的信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| umbraco | Umbraco-CMS | >= 14.0.0, < 14.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-48927 | 4.6 MEDIUM | Potential Code Execution Risk When Viewing SVG Files in Full Screen in Backoffice |
| CVE-2024-48929 | 4.2 MEDIUM | Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out |
| CVE-2024-48926 | 4.2 MEDIUM | Umbraco CMS logout page displayed before session expiration |
| CVE-2024-47819 | 4.2 MEDIUM | Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictiona |
No comments yet