Umbraco

Umbraco Cms

55 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.26%
  • Veröffentlicht 18.01.2022 17:15:10
  • Zuletzt bearbeitet 21.11.2024 06:47:16

The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so that it points to the attackers ...

  • EPSS 0.35%
  • Veröffentlicht 28.06.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:10:03

Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.

Exploit
  • EPSS 2.61%
  • Veröffentlicht 30.12.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:34:38

An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.

Exploit
  • EPSS 3.5%
  • Veröffentlicht 30.12.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:34:38

A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload.

Exploit
  • EPSS 0.42%
  • Veröffentlicht 30.12.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:34:38

A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by defaul...

  • EPSS 0.19%
  • Veröffentlicht 02.12.2020 02:15:11
  • Zuletzt bearbeitet 21.11.2024 05:24:02

Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Applications.Settings access.

Exploit
  • EPSS 2.16%
  • Veröffentlicht 16.03.2020 20:15:13
  • Zuletzt bearbeitet 21.11.2024 05:40:42

Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.

Exploit
  • EPSS 2.94%
  • Veröffentlicht 16.03.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:40:42

Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 23.01.2020 13:15:12
  • Zuletzt bearbeitet 21.11.2024 05:36:50

Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.

  • EPSS 0.39%
  • Veröffentlicht 27.11.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:54:09

Persistent cross-site scripting (XSS) vulnerability in Umbraco CMS 7.12.3 allows authenticated users to inject arbitrary web script via the Header Name of a content (Blog, Content Page, etc.). The vulnerability is exploited when updating or removing ...