The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to execute arbitrary ASP.NET code via a crafted SOAP request.
References
Configurations
Information
Published : 2014-12-27 10:59
Updated : 2014-12-30 03:21
NVD link : CVE-2013-4793
Mitre link : CVE-2013-4793
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
umbraco
- umbraco_cms