Under rare conditions, a restart of Umbraco can allow unauthorized users to gain admin-level permissions.
An unauthorized user gaining admin-level access and permissions to the backoffice.
10.6.1, 11.4.2, 12.0.1
*/install/*
and */umbraco/*
will limit the exposure to allowed IP addresses.{ "nvd_published_at": "2023-07-13T14:15:09Z", "cwe_ids": [ "CWE-284" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-07-13T17:02:07Z" }