CVE-2024-28868
Last modified
CVE-2024-28868 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue was fixed in version 10.8.5. As a workaround, one may disable the native login screen by exclusively using external logins.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Umbraco | Umbraco Cms | >= 10.0.0, < 10.8.5 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-28868?
How severe is CVE-2024-28868?
How do I fix CVE-2024-28868?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-28862The Ruby One Time Password library (ROTP) is an open source …5.5
- CVE-2024-28863node-tar is a Tar for Node.js. node-tar prior to version 6.2…6.5
- CVE-2024-28864SecureProps is a PHP library designed to simplify the encryp…2.6
- CVE-2024-28865django-wiki is a wiki system for Django. Installations of dj…7.5
- CVE-2024-28866GoCD is a continuous delivery server. GoCD versions from 19.…6.1
- CVE-2024-28867Swift Prometheus is a Swift client for the Prometheus monito…7.4
- CVE-2024-28869Traefik is an HTTP reverse proxy and load balancer. In affec…7.5
- CVE-2024-2887Type Confusion in WebAssembly in Google Chrome prior to 123.…7.7
- CVE-2024-28870Suricata is a network Intrusion Detection System, Intrusion …7.5
- CVE-2024-28871LibHTP is a security-aware parser for the HTTP protocol and …7.5
- CVE-2024-28872The TLS certificate validation code is flawed. An attacker c…8.1
- CVE-2024-28875A security flaw involving hard-coded credentials in LevelOne…8.1
Are you affected by CVE-2024-28868?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
