Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API
Vulnerability Description
Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0. The issue allows low-privilege users to access the webhook API and retrieve information that should be restricted to users with access to the settings section. Version 14.3.0 contains a patch.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-48925
Credits & Attribution
No credits recorded in the NVD database.
More from umbraco
View All →Affected Vendor
umbraco
View all reports →