Description
Umbraco workflow provides workflows for the Umbraco content management system. Prior to versions 10.3.9, 12.2.6, and 13.0.6, an Umbraco Backoffice user can modify requests to a particular API endpoint to include SQL, which will be executed by the server. Umbraco Workflow versions 10.3.9, 12.2.6, 13.0.6, as well as Umbraco Plumber version 10.1.2, contain a patch for this issue.
Published: 2024-04-24
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-1056 Umbraco workflow provides workflows for the Umbraco content management system. Prior to versions 10.3.9, 12.2.6, and 13.0.6, an Umbraco Backoffice user can modify requests to a particular API endpoint to include SQL, which will be executed by the server. Umbraco Workflow versions 10.3.9, 12.2.6, 13.0.6, as well as Umbraco Plumber version 10.1.2, contain a patch for this issue.
Github GHSA Github GHSA GHSA-287f-46j7-j4wh Umbraco Workflow's Backoffice users can execute arbitrary SQL
History

No history.

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T02:20:35.662Z

Reserved: 2024-04-19T14:07:11.229Z

Link: CVE-2024-32872

cve-icon Vulnrichment

Updated: 2024-07-03T18:23:54.762Z

cve-icon NVD

Status : Deferred

Published: 2024-04-24T15:15:48.003

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-32872

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses