CVE-2024-34071

EUVD-2024-1661
Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice before the vulnerable is exposed. This vulnerability has been patched in version(s) 8.18.14, 10.8.6, 12.3.10 and 13.3.1.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
Affected Products (NVD)
VendorProductVersion
umbracoumbraco_cms
8.18.5 ≤
𝑥
< 8.18.14
umbracoumbraco_cms
10.5.0 ≤
𝑥
< 10.8.6
umbracoumbraco_cms
12.0.0 ≤
𝑥
< 12.3.10
umbracoumbraco_cms
13.0.0 ≤
𝑥
< 13.3.1
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
umbracoumbraco_cms
8.18.5 ≤
𝑥
< 8.18.14
ADP
umbracoumbraco_cms
10.5.0 ≤
𝑥
< 10.8.6
ADP
umbracoumbraco_cms
12.0.0 ≤
𝑥
< 12.3.10
ADP
umbracoumbraco_cms
13.0.0 ≤
𝑥
< 13.3.1
ADP