Описание
Incorrect permission enforcement in UmbracoCms
Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Applications.Settings access.
Пакеты
Наименование
UmbracoCms
nuget
Затронутые версииВерсия исправления
< 8.10.0
8.10.0
Связанные уязвимости
CVSS3: 4.3
nvd
около 5 лет назад
Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Applications.Settings access.