CVE-2023-49278

Source
https://cve.org/CVERecord?id=CVE-2023-49278
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-49278.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-49278
Aliases
Published
2023-12-12T19:14:02.789Z
Modified
2026-08-12T03:51:19.812027746Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Umbraco CMS brute force exploit can be used to collect valid usernames
Details

Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, a brute force exploit can be used to collect valid usernames. Versions 8.18.10, 10.8.1, and 12.3.4 contain a patch for this issue.

Database specific
{
    "cwe_ids": [
        "CWE-200",
        "CWE-307"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49278.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/umbraco/umbraco-cms

Affected ranges

Type
GIT
Repo
https://github.com/umbraco/umbraco-cms
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.18.10"
        },
        {
            "introduced": "10.0.0"
        },
        {
            "fixed": "10.8.1"
        },
        {
            "introduced": "12.0.0"
        },
        {
            "fixed": "12.3.4"
        }
    ],
    "source": "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-49278.json"