Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice before the vulnerable is exposed. This vulnerability has been patched in version(s) 8.18.14, 10.8.6, 12.3.10 and 13.3.1.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1661 | Umbraco CMS Open Redirect Bypass Protection |
Github GHSA |
GHSA-j74q-mv2c-rxmp | Umbraco CMS Open Redirect Bypass Protection |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 12 Feb 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Umbraco
Umbraco umbraco Cms |
|
| CPEs | cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Umbraco
Umbraco umbraco Cms |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T02:42:59.968Z
Reserved: 2024-04-30T06:56:33.381Z
Link: CVE-2024-34071
Updated: 2024-08-02T02:42:59.968Z
Status : Analyzed
Published: 2024-05-21T14:15:11.783
Modified: 2025-02-12T15:39:05.367
Link: CVE-2024-34071
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA