CVE-2023-48227
Umbraco CMS Backoffice User can bypass "Publish" restriction
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.3.0, Backoffice users with send for approval permission but not publish permission are able to publish in some scenarios. Versions 8.18.10, 10.7.0, and 12.3.0 contains a patch for this issue. No known workarounds are available.
Umbraco es un sistema de gestión de contenidos (CMS) ASP.NET. A partir de la versión 8.0.0 y anteriores a las versiones 8.18.10, 10.7.0 y 12.3.0, los usuarios de Backoffice con permiso de envío para aprobación pero sin permiso de publicación pueden publicar en algunos escenarios. Las versiones 8.18.10, 10.7.0 y 12.3.0 contienen un parche para este problema. No hay workarounds disponibles.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-11-13 CVE Reserved
- 2023-12-12 CVE Published
- 2024-08-28 CVE Updated
- 2024-11-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-335x-5wcm-8jv2 | Url Repurposed |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Umbraco Search vendor "Umbraco" | Umbraco Cms Search vendor "Umbraco" for product "Umbraco Cms" | >= 8.0.0 < 8.18.10 Search vendor "Umbraco" for product "Umbraco Cms" and version " >= 8.0.0 < 8.18.10" | - |
Affected
| ||||||
Umbraco Search vendor "Umbraco" | Umbraco Cms Search vendor "Umbraco" for product "Umbraco Cms" | >= 9.0.0 < 10.7.0 Search vendor "Umbraco" for product "Umbraco Cms" and version " >= 9.0.0 < 10.7.0" | - |
Affected
| ||||||
Umbraco Search vendor "Umbraco" | Umbraco Cms Search vendor "Umbraco" for product "Umbraco Cms" | >= 11.0.0 < 12.3.0 Search vendor "Umbraco" for product "Umbraco Cms" and version " >= 11.0.0 < 12.3.0" | - |
Affected
|