Skip to content

Possible user enumeration

Low
bergmania published GHSA-552f-97wf-pmpq Mar 20, 2024

Package

nuget UmbracoCMS (NuGet)

Affected versions

>10.0.0

Patched versions

10.8.5

Description

Impact

What kind of vulnerability is it? Who is impacted?
A user enumeration attack is possible.

Affected versions

Umbraco 10 with access to the native login screen

Patches

This is fixed in 10.8.5

Workarounds

Disabling the native login screen, by exclusively use external logins.

Severity

Low
3.7
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE ID

CVE-2024-28868

Weaknesses

Credits