CVE-2013-4793

Umbraco CMS < 6.0.3 - Unauthenticated Remote Code Execution via TemplateService SOAP Request

Title source: llm
STIX 2.1

Description

The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to execute arbitrary ASP.NET code via a crafted SOAP request.

References (1)

Core 1

Scores

EPSS 0.0142
EPSS Percentile 69.5%

Details

CWE
CWE-287
Status published
Products (1)
umbraco/umbraco_cms < 6.0.3
Published Dec 27, 2014
Tracked Since Feb 18, 2026