CVE-2020-7210: CSRF
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7210?
CVE-2020-7210 is a vulnerability in Umbraco CMS 8.2.2 that allows CSRF to enable/disable or delete user accounts.
How severe is CVE-2020-7210?
CVE-2020-7210 has a severity level of 4.3 out of 10, which is considered medium.
How does CVE-2020-7210 allow CSRF attacks?
CVE-2020-7210 allows CSRF attacks by enabling an attacker to perform actions on behalf of an authenticated user without their consent or knowledge.
Is there a fix available for CVE-2020-7210?
Yes, Umbraco CMS users should upgrade to a version that contains the security fix for CVE-2020-7210.
Where can I find more information about CVE-2020-7210?
You can find more information about CVE-2020-7210 at the following references: [1](http://packetstormsecurity.com/files/156062/Umbraco-CMS-8.2.2-Cross-Site-Request-Forgery.html), [2](http://seclists.org/fulldisclosure/2020/Jan/33), [3](https://sec-consult.com/en/blog/advisories/cross-site-request-forgery-csrf-in-umbraco-cms/).