Under rare conditions, a restart of Umbraco can allow unauthorized users to gain admin-level permissions.
An unauthorized user gaining admin-level access and permissions to the backoffice.
10.6.1, 11.4.2, 12.0.1
*/install/* and */umbraco/* will limit the exposure to allowed IP addresses.{
"cwe_ids": [
"CWE-284"
],
"github_reviewed": true,
"github_reviewed_at": "2023-07-13T17:02:07Z",
"nvd_published_at": "2023-07-13T14:15:09Z",
"severity": "HIGH"
}