CVE-2024-48925: Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API
Impact An improper access control issue has been identified, allowing low-privilege users to access the webhook API and retrieve information that should be restricted to users with access to the settings section
Other sources
Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0. The issue allows low-privilege users to access the webhook API and retrieve information that should be restricted to users with access to the settings section. Version 14.3.0 contains a patch.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48925?
CVE-2024-48925 is identified as a vulnerability with improper access control, which could significantly impact the security of Umbraco CMS.
How do I fix CVE-2024-48925?
To fix CVE-2024-48925, update Umbraco CMS to version 14.3.0 or later.
Who is affected by CVE-2024-48925?
CVE-2024-48925 affects users of Umbraco CMS versions 14.0.0 to 14.3.0.
What is the impact of CVE-2024-48925?
The impact of CVE-2024-48925 is that low-privilege users may access webhook API information that should be restricted.
When was CVE-2024-48925 disclosed?
CVE-2024-48925 was disclosed as part of Umbraco's security advisories addressing access control issues.