CVE-2023-49273

MEDIUM

Umbraco <8.0.0-8.18.10-10.8.1-12.3.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, users with low privileges (Editor, etc.) are able to access some unintended endpoints. Versions 8.18.10, 10.8.1, and 12.3.4 contain a patch for this issue.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0026
EPSS Percentile 49.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-863
Status published
Products (2)
nuget/Umbraco.CMS 8.0.0 - 8.18.10NuGet
umbraco/umbraco_cms 8.0.0 - 8.18.10
Published Dec 12, 2023
Tracked Since Feb 18, 2026