Описание
Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue was fixed in version 10.8.5. As a workaround, one may disable the native login screen by exclusively using external logins.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 10.0.0 (включая) до 10.8.5 (исключая)
cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00229
Низкий
3.7 Low
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-204
CWE-203
Связанные уязвимости
EPSS
Процентиль: 45%
0.00229
Низкий
3.7 Low
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-204
CWE-203