PT-2019-6207 · Umbraco · Umbraco Cms

A. Melnikova

·

Published

2019-11-28

·

Updated

2022-05-24

·

CVE-2020-7210

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Umbraco CMS version 8.2.2
Description The issue is related to a cross-site request forgery (CSRF) flaw. This flaw can be exploited by a remote attacker using a specially crafted web page to enable, disable, or delete user accounts.
Recommendations For Umbraco CMS version 8.2.2, consider implementing anti-CSRF measures to prevent exploitation until a patch is available. As a temporary workaround, restrict access to user account management functionality to minimize the risk of unauthorized modifications.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02397
CVE-2020-7210
GHSA-GQQF-8CX6-9R7H

Affected Products

Umbraco Cms