Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1056 | Umbraco workflow provides workflows for the Umbraco content management system. Prior to versions 10.3.9, 12.2.6, and 13.0.6, an Umbraco Backoffice user can modify requests to a particular API endpoint to include SQL, which will be executed by the server. Umbraco Workflow versions 10.3.9, 12.2.6, 13.0.6, as well as Umbraco Plumber version 10.1.2, contain a patch for this issue. |
Github GHSA |
GHSA-287f-46j7-j4wh | Umbraco Workflow's Backoffice users can execute arbitrary SQL |
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T02:20:35.662Z
Reserved: 2024-04-19T14:07:11.229Z
Link: CVE-2024-32872
Updated: 2024-07-03T18:23:54.762Z
Status : Deferred
Published: 2024-04-24T15:15:48.003
Modified: 2026-06-17T07:30:35.603
Link: CVE-2024-32872
No data.
OpenCVE Enrichment
No data.
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
EUVD
Github GHSA