Improper access control in Umbraco CMS - #VU23469
Published: December 10, 2019
Umbraco CMS
Detailed vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the Miniprofiler plugin. A remote unauthenticated attacker can send a direct request to the application and obtain sensitive information, such as SQL query data, email addresses of users.