Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-34071


Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice before the vulnerable is exposed. This vulnerability has been patched in version(s) 8.18.14, 10.8.6, 12.3.10 and 13.3.1.


Published

2024-05-21T14:15:11.783

Last Modified

2025-02-12T15:39:05.367

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-601
  • Type: Primary
    CWE-601

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application umbraco umbraco_cms < 8.18.14 Yes
Application umbraco umbraco_cms < 10.8.6 Yes
Application umbraco umbraco_cms < 12.3.10 Yes
Application umbraco umbraco_cms < 13.3.1 Yes

References