VulnerabilityAnalyzed
CVE-2024-28868
Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack.
MEDIUM 5.3EPSS 0.45%
Does this matter?
Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.
Description
Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue was fixed in version 10.8.5. As a workaround, one may disable the native login screen by exclusively using external logins.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-204, CWE-203
- Affected
- umbraco/umbraco cms
- Source
- security-advisories@github.com
References
- https://github.com/umbraco/Umbraco-CMS/commit/7e1d1a1968000226cd882fff078b122b8d46c44dPatch
- https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-552f-97wf-pmpqVendor Advisory
- https://github.com/umbraco/Umbraco-CMS/commit/7e1d1a1968000226cd882fff078b122b8d46c44dPatch
- https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-552f-97wf-pmpqVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.