CVE-2013-4793: High severity umbraco cms vulnerability
The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to execute arbitrary ASP.NET code via a crafted SOAP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4793?
CVE-2013-4793 is considered a critical vulnerability due to its ability to allow remote attackers to execute arbitrary ASP.NET code.
How do I fix CVE-2013-4793?
To fix CVE-2013-4793, you should upgrade Umbraco CMS to version 6.0.4 or later.
What versions of Umbraco CMS are affected by CVE-2013-4793?
CVE-2013-4793 affects all versions of Umbraco CMS prior to 6.0.4.
How does CVE-2013-4793 allow remote code execution?
CVE-2013-4793 allows remote code execution due to the lack of authentication required in the update function of the TemplateService component.
Is there a workaround for CVE-2013-4793?
There are no reliable workarounds for CVE-2013-4793, and upgrading to a patched version is the recommended action.