CVE-2015-8814: CSRF
Umbraco before 7.4.0 allows remote attackers to bypass anti-forgery security measures and conduct cross-site request forgery (CSRF) attacks as demonstrated by editing user account information in the templates.asmx.cs file.
Other sources
Umbraco before 7.4.0 allows remote attackers to bypass anti-forgery security measures and conduct cross-site request forgery (CSRF) attacks as demonstrated by editing user account information in the templates.asmx.cs file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8814?
CVE-2015-8814 is considered a high-severity vulnerability due to its potential to allow cross-site request forgery (CSRF) attacks.
How do I fix CVE-2015-8814?
The recommended fix for CVE-2015-8814 is to upgrade to Umbraco version 7.4.0 or later.
What types of attacks can exploit CVE-2015-8814?
CVE-2015-8814 can be exploited for cross-site request forgery (CSRF) attacks, allowing unauthorized actions on behalf of users.
Which versions of Umbraco are affected by CVE-2015-8814?
Versions of Umbraco before 7.4.0, including 7.3.8, are affected by CVE-2015-8814.
Who is primarily impacted by CVE-2015-8814?
Organizations using affected versions of Umbraco CMS are primarily impacted by CVE-2015-8814 due to the security flaw.