GHSA-cfr5-7p54-4qg8

    Dashboard / Vulnerabilities / GHSA-cfr5-7p54-4qg8

    GHSA-cfr5-7p54-4qg8

    Published: 13 Dec 2023Last Modified: 16 Feb 2024

    Summary: Privilege Escalation using Spoofing

    Details: #### Impact Users with low privileges ( Editor, etc) are able to access some unintended endpoints. #### Explanation of the vulnerability Possible to delete redirect urls, when disabled by admin with only access to backoffice Possible to access the examine dashboard with only access to backoffice Possible to access the published cache dashboard with only access to backoffice Possible to access the telemetry dashboard with only access to backoffice Possible to access the languages with only access to backoffice Possible to access the stylesheets with only access to backoffice

    Affected packages

    Package

    Name: Umbraco.CMS

    Purl: pkg:nuget/Umbraco.CMS

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 8.0.0
    Fixed -8.18.10

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-cfr5-7p54-4qg8 | CVE-DB