Umbraco.Cms is vulnerable to Incorrect Authorization
88
High Risk
Umbraco.Cms Management API template create, update, and delete endpoints allow Content-only backoffice users to mutate Templates. Those operations should require Settings-section access. Under the default BackofficeDevelopment runtime mode, template content is compiled as Razor and executed on the server, which can lead to remote code execution. The fix requires Settings-section authorization on template mutations and related Settings-only Management API operations.
You are affected if you are using a version that falls within the vulnerable range.
Umbraco.Cms is vulnerable to Incorrect Authorization in versions 15.2.0 - 17.6.1 and 18.0.0 - 18.1.0.
Upgrade the Umbraco.Cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.