Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.3.0, Backoffice users with send for approval permission but not publish permission are able to publish in some scenarios. Versions 8.18.10, 10.7.0, and 12.3.0 contains a patch for this issue. No known workarounds are available.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3077 | Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.3.0, Backoffice users with send for approval permission but not publish permission are able to publish in some scenarios. Versions 8.18.10, 10.7.0, and 12.3.0 contains a patch for this issue. No known workarounds are available. |
Github GHSA |
GHSA-335x-5wcm-8jv2 | Backoffice User can bypass "Publish" restriction |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-28T14:47:00.241Z
Reserved: 2023-11-13T13:25:18.480Z
Link: CVE-2023-48227
Updated: 2024-08-02T21:23:39.481Z
Status : Modified
Published: 2023-12-12T17:15:08.143
Modified: 2024-11-21T08:31:15.163
Link: CVE-2023-48227
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA