Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.4 NuGet

Umbraco CMS Improper Access Control vulnerability

GHSA-hrww-x3fq-xcvh · CVE-2024-43377

Published · Modified

Description

Impact

As an authenticated user one can access a few unintended endpoints

Explanation of the vulnerability

Few endpoints in Umbraco Management API was not protected by a specific section. These just required you to be authenticated. Due to the fact that a member is also just authenticated, it was possible to get info from these endpoints using a member token.

Ready to move

Start Securing

Free, no credit card | First findings in minutes