First published: Wed Dec 02 2020(Updated: )
Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Applications.Settings access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Umbraco CMS | >=8.0.0<=8.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-29454 is a vulnerability in Umbraco CMS versions 8.0.0 through 8.9.1 that allows a user to access a logviewer endpoint without proper access.
An attacker can exploit CVE-2020-29454 by visiting the logviewer endpoint even if they do not have the necessary access rights.
CVE-2020-29454 has a severity rating of medium with a score of 4.3.
Umbraco CMS versions 8.0.0 through 8.9.1 are affected by CVE-2020-29454.
Yes, the fix for CVE-2020-29454 is available in the Umbraco CMS patch release version 8.9.1.