Umbraco Workflow's Backoffice users can execute arbitrary SQL
Moderate severity
GitHub Reviewed
Published
Apr 24, 2024
in
umbraco/Umbraco.Workflow.Issues
•
Updated Apr 24, 2024
Description
Published by the National Vulnerability Database
Apr 24, 2024
Published to the GitHub Advisory Database
Apr 24, 2024
Reviewed
Apr 24, 2024
Last updated
Apr 24, 2024
Impact
Backoffice users can execute arbitrary SQL.
Explanation of the vulnerability
A Backoffice user can modify requests to a particular API endpoint to include SQL which will be executed by the server.
Affected versions
All versions
Patches
Workflow 10.3.9, 12.2.6, 13.0.6, Plumber 10.1.2
References
Upgrading Umbraco Workflow
References