HomeUmbracoCVE-2024-48926

CVE-2024-48926

MEDIUM
4.2CVSS
Published: 2024-10-22
Updated: 2024-10-25
AI Analysis

Description

Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.18.15. The Backoffice displays the logout page with a session timeout message before the server session has fully expired, causing users to believe they have been logged out approximately 30 seconds before they actually are. Versions 13.5.2, 10.8,7, and 8.18.15 contain a patch for the issue.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Vector
network
Complexity
high
Privileges
none
User Action
required
Scope
unchanged
Confidentiality
low
Integrity
low
Availability
none
Weaknesses
CWE-613

Metadata

Primary Vendor
UMBRACO
Published
10/22/2024
Last Modified
10/25/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

umbraco : umbraco_cmsumbraco : umbraco_cmsumbraco : umbraco_cms

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2024-48926 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com