Umbraco workflow provides workflows for the Umbraco content management system. Prior to versions 10.3.9, 12.2.6, and 13.0.6, an Umbraco Backoffice user can modify requests to a particular API endpoint to include SQL, which will be executed by the server. Umbraco Workflow versions 10.3.9, 12.2.6, 13.0.6, as well as Umbraco Plumber version 10.1.2, contain a patch for this issue.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-1056 Umbraco workflow provides workflows for the Umbraco content management system. Prior to versions 10.3.9, 12.2.6, and 13.0.6, an Umbraco Backoffice user can modify requests to a particular API endpoint to include SQL, which will be executed by the server. Umbraco Workflow versions 10.3.9, 12.2.6, 13.0.6, as well as Umbraco Plumber version 10.1.2, contain a patch for this issue.
Github GHSA Github GHSA GHSA-287f-46j7-j4wh Umbraco Workflow's Backoffice users can execute arbitrary SQL
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T02:20:35.662Z

Reserved: 2024-04-19T14:07:11.229Z

Link: CVE-2024-32872

cve-icon Vulnrichment

Updated: 2024-07-03T18:23:54.762Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-24T15:15:48.003

Modified: 2024-11-21T09:15:54.530

Link: CVE-2024-32872

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses