Author: Angelo Barbosa

CVE-2023-49279 | Umbraco CMS up to 7.15.10/8.18.8/10.6.x/11.4.x/12.1.x SVG File cross site scripting (GHSA-6xmx-85×3-4cv2)

A vulnerability was found in Umbraco CMS up to 7.15.10/8.18.8/10.6.x/11.4.x/12.1.x and classified as problematic. This issue affects some unknown processing of the component SVG File Handler. The manipulation leads to cross site scripting. The identification of this vulnerability is CVE-2023-49279. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-49274 | Umbraco CMS up to 8.18.9 Reset Password information disclosure (GHSA-8qp8-9rpw-j46c)

A vulnerability has been found in Umbraco CMS up to 8.18.9 and classified as problematic. This vulnerability affects unknown code of the component Reset Password Handler. The manipulation leads to information disclosure. This vulnerability was named CVE-2023-49274. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-49273 | Umbraco CMS up to 8.18.9/10.8.0/12.3.3 authorization (GHSA-cfr5-7p54-4qg8)

A vulnerability, which was classified as critical, was found in Umbraco CMS up to 8.18.9/10.8.0/12.3.3. This affects an unknown part. The manipulation leads to incorrect authorization. This vulnerability is uniquely identified as CVE-2023-49273. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-49089 | Umbraco CMS up to 8.18.9/10.8.0/12.2.x path traversal (GHSA-6324-52pr-h4p5)

A vulnerability, which was classified as critical, has been found in Umbraco CMS up to 8.18.9/10.8.0/12.2.x. Affected by this issue is some unknown functionality. The manipulation leads to path traversal. This vulnerability is handled as CVE-2023-49089. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-49278 | Umbraco CMS up to 8.18.9/10.8.0/12.3.3 information disclosure (GHSA-7×74-h8cw-qhxq)

A vulnerability classified as problematic was found in Umbraco CMS up to 8.18.9/10.8.0/12.3.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure. This vulnerability is known as CVE-2023-49278. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More