CVE-2024-34071

MEDIUM

Umbraco - Open Redirect

Title source: llm
STIX 2.1

Description

Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice before the vulnerable is exposed. This vulnerability has been patched in version(s) 8.18.14, 10.8.6, 12.3.10 and 13.3.1.

Scores

CVSS v3 6.1
EPSS 0.0052
EPSS Percentile 67.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (3)
nuget/Umbraco.Cms.Web.BackOffice 8.18.5 - 8.18.14NuGet
nuget/UmbracoCms.Core 8.18.5 - 8.18.14NuGet
umbraco/umbraco_cms 8.18.5 - 8.18.14
Published May 21, 2024
Tracked Since Feb 18, 2026