Umbraco.Cms.Web.Backoffice is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
49
Medium Risk
Authenticated backoffice users can exploit manipulated API URLs to bypass access restrictions, allowing them to retrieve or delete content and media stored in folders they are not authorized to access.
You are affected if you are using a version that falls within the vulnerable range.
Umbraco.Cms.Web.Backoffice is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 9.0.0 - 10.8.8, 11.0.0 - 13.7.0, 14.0.0 - 14.3.2 and 15.0.0 - 15.2.2.
Upgrade the Umbraco.Cms.Web.Backoffice library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant