Umbraco CMS是丹麦Umbraco公司的一个内容管理系统。 Umbraco CMS存在注入漏洞,该漏洞源于存在远程代码执行问题,用户在全屏模式下预览SVG文件时可能会面临代码执行风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| umbraco | Umbraco-CMS | >= 13.0.0, < 13.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-48929 | 4.2 MEDIUM | Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out |
| CVE-2024-48926 | 4.2 MEDIUM | Umbraco CMS logout page displayed before session expiration |
| CVE-2024-47819 | 4.2 MEDIUM | Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictiona |
| CVE-2024-48925 | Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Web |
No comments yet