Description
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, a user enumeration attack is possible when SMTP is not set up correctly, but reset password is enabled. Versions 8.18.10, 10.8.1, and 12.3.4 contain a patch for this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3163 | Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, a user enumeration attack is possible when SMTP is not set up correctly, but reset password is enabled. Versions 8.18.10, 10.8.1, and 12.3.4 contain a patch for this issue. |
Github GHSA |
GHSA-8qp8-9rpw-j46c | SMTP misconfiguration leading to "Forgot Password" exploit that leaks registered user email. |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T21:53:44.983Z
Reserved: 2023-11-24T16:45:24.311Z
Link: CVE-2023-49274
No data.
Status : Modified
Published: 2023-12-12T20:15:07.993
Modified: 2024-11-21T08:33:09.790
Link: CVE-2023-49274
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA