Impact Umbraco have an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice, before the vulnerability is exposed.
Affected Version
\>= 8.18.5, >= 10.5.0, >= 12.0.0, >= 13.0.0
Patches 8.18.14, 10.8.6, 12.3.10, 13.3.1
Impact Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical. Affected Versions Umbraco versions 13.0.0 - 13.1.1
Patches 13.1.1
Workarounds Disabling webhooks functionality.
Impact Stored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application.
Affected versions Umbraco CMS >= 8.00
Patches This is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer