← back
CVE-2024-29035mediumCWE-918

Umbraco's Blind SSRF Leads to Port Scan by using Webhooks

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.1epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
Umbraco is an ASP.NET CMS. Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical. This vulnerability is fixed in 13.1.1.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Affected products
umbraco · Umbraco-CMS