Description
Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue was fixed in version 10.8.5. As a workaround, one may disable the native login screen by exclusively using external logins.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0821 | Umbraco possible user enumeration |
Github GHSA |
GHSA-552f-97wf-pmpq | Umbraco possible user enumeration |
References
History
Wed, 12 Feb 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Umbraco
Umbraco umbraco Cms |
|
| Weaknesses | CWE-203 | |
| CPEs | cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Umbraco
Umbraco umbraco Cms |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T00:56:58.154Z
Reserved: 2024-03-11T22:45:07.687Z
Link: CVE-2024-28868
Updated: 2024-08-02T00:56:58.154Z
Status : Analyzed
Published: 2024-03-20T20:15:09.110
Modified: 2025-02-12T15:23:09.683
Link: CVE-2024-28868
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA