#VU23469 Improper access control in Umbraco CMS
Published: December 10, 2019
Umbraco CMS
Umbraco
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the Miniprofiler plugin. A remote unauthenticated attacker can send a direct request to the application and obtain sensitive information, such as SQL query data, email addresses of users.