First published: Tue Oct 22 2024(Updated: )
### Impact An improper access control issue has been identified, allowing low-privilege users to access the webhook API and retrieve information that should be restricted to users with access to the settings section
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Umbraco.CMS | >=14.0.0<14.3.0 | 14.3.0 |
Umbraco CMS | >=14.0.0<14.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48925 is identified as a vulnerability with improper access control, which could significantly impact the security of Umbraco CMS.
To fix CVE-2024-48925, update Umbraco CMS to version 14.3.0 or later.
CVE-2024-48925 affects users of Umbraco CMS versions 14.0.0 to 14.3.0.
The impact of CVE-2024-48925 is that low-privilege users may access webhook API information that should be restricted.
CVE-2024-48925 was disclosed as part of Umbraco's security advisories addressing access control issues.