Description
Umbraco workflow provides workflows for the Umbraco content management system. Prior to versions 10.3.9, 12.2.6, and 13.0.6, an Umbraco Backoffice user can modify requests to a particular API endpoint to include SQL, which will be executed by the server. Umbraco Workflow versions 10.3.9, 12.2.6, 13.0.6, as well as Umbraco Plumber version 10.1.2, contain a patch for this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1056 | Umbraco workflow provides workflows for the Umbraco content management system. Prior to versions 10.3.9, 12.2.6, and 13.0.6, an Umbraco Backoffice user can modify requests to a particular API endpoint to include SQL, which will be executed by the server. Umbraco Workflow versions 10.3.9, 12.2.6, 13.0.6, as well as Umbraco Plumber version 10.1.2, contain a patch for this issue. |
Github GHSA |
GHSA-287f-46j7-j4wh | Umbraco Workflow's Backoffice users can execute arbitrary SQL |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T02:20:35.662Z
Reserved: 2024-04-19T14:07:11.229Z
Link: CVE-2024-32872
Updated: 2024-07-03T18:23:54.762Z
Status : Deferred
Published: 2024-04-24T15:15:48.003
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-32872
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA