PT-2019-6207 · Umbraco · Umbraco Cms
A. Melnikova
·
Published
2019-11-28
·
Updated
2022-05-24
·
CVE-2020-7210
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Umbraco CMS version 8.2.2
Description
The issue is related to a cross-site request forgery (CSRF) flaw. This flaw can be exploited by a remote attacker using a specially crafted web page to enable, disable, or delete user accounts.
Recommendations
For Umbraco CMS version 8.2.2, consider implementing anti-CSRF measures to prevent exploitation until a patch is available. As a temporary workaround, restrict access to user account management functionality to minimize the risk of unauthorized modifications.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Umbraco Cms