Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pjez-Qestit

#45982of 53,632
5.5Total CVSS
Vulnerabilities · 1
PT-2024-24928
5.5
2024-04-24
Umbraco · Umbraco Workflow · CVE-2024-32872
**Name of the Vulnerable Software and Affected Versions** Umbraco Workflow versions prior to 10.3.9 Umbraco Workflow versions prior to 12.2.6 Umbraco Workflow versions prior to 13.0.6 **Description** The issue allows an Umbraco Backoffice user to modify requests to a particular API endpoint to include SQL, which will be executed by the server. This enables the execution of arbitrary SQL. **Recommendations** For Umbraco Workflow versions prior to 10.3.9, update to version 10.3.9 or later. For Umbraco Workflow versions prior to 12.2.6, update to version 12.2.6 or later. For Umbraco Workflow versions prior to 13.0.6, update to version 13.0.6 or later.