HomeUmbracoCVE-2024-48925

CVE-2024-48925

NONE
0.0CVSS
Published: 2024-10-22
Updated: 2024-10-25
AI Analysis

Description

Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0. The issue allows low-privilege users to access the webhook API and retrieve information that should be restricted to users with access to the settings section. Version 14.3.0 contains a patch.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N
Attack Vector
network
Complexity
low
Privileges
low
User Action
none
Scope
unchanged
Confidentiality
none
Integrity
none
Availability
none
Weaknesses
CWE-284CWE-863

Metadata

Primary Vendor
UMBRACO
Published
10/22/2024
Last Modified
10/25/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

umbraco : umbraco_cms

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2024-48925 | NONE Severity | CVEDatabase.com | CVEDatabase.com