Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
Moderate severity
GitHub Reviewed
Published
Mar 11, 2025
in
umbraco/Umbraco-CMS
•
Updated Mar 12, 2025
Package
Affected versions
<= 10.8.8
>= 11.0.0-rc1, <= 13.7.0
Patched versions
10.8.9
13.7.1
Description
Published to the GitHub Advisory Database
Mar 11, 2025
Reviewed
Mar 11, 2025
Last updated
Mar 12, 2025
Impact
Via manipulation of backoffice API URLs it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to.
Patches
Will be patched in 10.8.9 and 13.7.1
Workarounds
None available.
References