Umbraco.Cms is vulnerable to Information Disclosure
15
Low Risk
Affected versions of this package are vulnerable to information disclosure due to improper access controls that allow back-office users without proper webhook permissions to access webhook logs due to insufficient access controls. Additionally, the application fails to properly validate file system paths, exposing resolved paths and potentially allowing directory traversal attacks. An attacker with back-office access, even without webhook privileges, can read sensitive webhook logs or access arbitrary files on the system. It leads to information disclosure or server compromise.
You are affected if you are using a version that falls within the vulnerable range.
Umbraco.Cms is vulnerable to Information Disclosure in versions 9.3.0 - 15.3.1.
Upgrade the Umbraco.Cms library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant