Umbraco before 7.4.0 allows remote attackers to bypass anti-forgery security measures and conduct cross-site request forgery (CSRF) attacks as demonstrated by editing user account information in the templates.asmx.cs file.
References
Configurations
History
No history.
Information
Published : 2017-03-03 16:59
Updated : 2025-04-20 01:37
NVD link : CVE-2015-8814
Mitre link : CVE-2015-8814
CVE.ORG link : CVE-2015-8814
JSON object : View
Products Affected
umbraco
- umbraco
CWE
CWE-352
Cross-Site Request Forgery (CSRF)