First published: Thu Jan 23 2020(Updated: )
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Umbraco CMS | =8.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7210 is a vulnerability in Umbraco CMS 8.2.2 that allows CSRF to enable/disable or delete user accounts.
CVE-2020-7210 has a severity level of 4.3 out of 10, which is considered medium.
CVE-2020-7210 allows CSRF attacks by enabling an attacker to perform actions on behalf of an authenticated user without their consent or knowledge.
Yes, Umbraco CMS users should upgrade to a version that contains the security fix for CVE-2020-7210.
You can find more information about CVE-2020-7210 at the following references: [1](http://packetstormsecurity.com/files/156062/Umbraco-CMS-8.2.2-Cross-Site-Request-Forgery.html), [2](http://seclists.org/fulldisclosure/2020/Jan/33), [3](https://sec-consult.com/en/blog/advisories/cross-site-request-forgery-csrf-in-umbraco-cms/).