MEDIUM 4.3 NuGet
Umbraco CMS vulnerable to CSRF
GHSA-gqqf-8cx6-9r7h · CVE-2020-7210
Published · Modified
Description
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2020-7210
- PACKAGE https://github.com/umbraco/Umbraco-CMS
- WEB https://sec-consult.com/en/blog/advisories/cross-site-request-forgery-csrf-in-umbraco-cms
- WEB https://seclists.org/bugtraq/2020/Jan/35
- WEB http://packetstormsecurity.com/files/156062/Umbraco-CMS-8.2.2-Cross-Site-Request-Forgery.html
- WEB http://seclists.org/fulldisclosure/2020/Jan/33
Ready to move
Start Securing
Free, no credit card | First findings in minutes