← Back

CVE-2023-48227

nvd nist
Published: Dec 12, 2023Modified: Nov 21, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.3.0, Backoffice users with send for approval permission but not publish permission are able to publish in some scenarios. Versions 8.18.10, 10.7.0, and 12.3.0 contains a patch for this issue. No known workarounds are available.

Affected (3)

Products: Umbraco: Umbraco Cms
1 product
Umbraco Cms
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Umbraco
From 11.0.0 to 12.3.0
From 8.0.0 to 8.18.10
From 9.0.0 to 10.7.0

References (2)

Source: security-advisories@github.com
URL Repurposed
Source: af854a3a-2127-422b-91ae-364da2661108
URL Repurposed

Timeline

No history available yet.