Umbraco
cpe:2.3:a:umbraco:umbraco:*:*:*:*:*:*:*, +1 more
- <= 15.2.2
- <= 14.3.2
A vulnerability exists in Umbraco's API management package, specifically in versions prior to 15.2.3 and 14.3.3. The issue stems from improper API access control, which enables low-privilege, authenticated users to create and update data type information. This functionality should be reserved for users with access to the settings section.
Exploitation of this vulnerability could lead to unauthorized modifications of data type information by low-privilege users.
Users can upgrade to Umbraco versions 15.2.3 or 14.3.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.