First published: Thu Jul 13 2023(Updated: )
Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerability was patched in versions 10.6.1, 11.4.2 and 12.0.1.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Umbraco CMS | >=10.0.0<10.6.1 | |
Umbraco CMS | >=11.0.0<11.4.2 | |
Umbraco CMS | >=12.0.0<12.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37267 is a vulnerability in Umbraco CMS that can allow unauthorized users access to admin-level permissions.
CVE-2023-37267 is considered a critical vulnerability with a severity score of 9.8.
Under rare conditions, a restart of Umbraco CMS can allow unauthorized users access to admin-level permissions.
Umbraco CMS versions 10.0.0 to 10.6.1, 11.0.0 to 11.4.2, and 12.0.0 to 12.0.1 are affected by CVE-2023-37267.
You can fix CVE-2023-37267 by updating your Umbraco CMS to versions 10.6.1, 11.4.2, or 12.0.1, where the vulnerability has been patched.