GHSA-jrmq-rv9w-63rv

    Dashboard / Vulnerabilities / GHSA-jrmq-rv9w-63rv

    GHSA-jrmq-rv9w-63rv

    Published: 21 Jan 2022Last Modified: 19 Feb 2024

    Summary: Umbraco ApplicationURL Overwrite

    Details: Within the Umbraco CMS, a configuration element named "UmbracoApplicationUrl" (or just "ApplicationUrl") is used whenever application code needs to build a URL pointing back to the site. For example, when a user resets their password and the application builds a password reset URL or when the administrator invites users to the site. For Umbraco versions less than 9.2.0, if the Application URL is not specifically configured, the attacker can manipulate this value and store it persistently affecting all users for components where the "UmbracoApplicationUrl" is used. For example, the attacker is able to change the URL users receive when resetting their password so that it points to the attackers server, when the user follows this link the reset token can be intercepted by the attacker resulting in account takeover.

    Affected packages

    Package

    Name: Umbraco.Cms.Core

    Purl: pkg:nuget/Umbraco.Cms.Core

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -9.2.0

    Affected versions

    9.0.0
    9.0.0-rc001
    9.0.0-rc002
    9.0.0-rc003
    9.0.0-rc004
    9.0.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-jrmq-rv9w-63rv | CVE-DB