MEDIUM 5.4 NuGet
Umbraco CMS Improper Access Control vulnerability
GHSA-hrww-x3fq-xcvh · CVE-2024-43377
Published · Modified
Description
Impact
As an authenticated user one can access a few unintended endpoints
Explanation of the vulnerability
Few endpoints in Umbraco Management API was not protected by a specific section. These just required you to be authenticated. Due to the fact that a member is also just authenticated, it was possible to get info from these endpoints using a member token.
Ready to move
Start Securing
Free, no credit card | First findings in minutes