Umbraco CMS是丹麦Umbraco公司的一个内容管理系统。 Umbraco CMS存在授权问题漏洞,该漏洞源于在显式注销期间,服务器会话不会完全终止。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| umbraco | Umbraco-CMS | >= 13.0.0, < 13.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-48927 | 4.6 MEDIUM | Potential Code Execution Risk When Viewing SVG Files in Full Screen in Backoffice |
| CVE-2024-48926 | 4.2 MEDIUM | Umbraco CMS logout page displayed before session expiration |
| CVE-2024-47819 | 4.2 MEDIUM | Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictiona |
| CVE-2024-48925 | Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Web |
No comments yet