CVE-2024-28868
Last modified
CVE-2024-28868 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue was fixed in version 10.8.5. As a workaround, one may disable the native login screen by exclusively using external logins.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Umbraco | Umbraco Cms | >= 10.0.0, < 10.8.5 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-28868?
How severe is CVE-2024-28868?
How do I fix CVE-2024-28868?
Are you affected by CVE-2024-28868?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
