Vulnerability Description
The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to execute arbitrary ASP.NET code via a crafted SOAP request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Umbraco | Umbraco Cms | <= 6.0.3 |
Related Weaknesses (CWE)
References
- https://labs.mwrinfosecurity.com/advisories/2013/11/29/umbraco-cms-templateservi
- https://labs.mwrinfosecurity.com/advisories/2013/11/29/umbraco-cms-templateservi
FAQ
What is CVE-2013-4793?
CVE-2013-4793 is a vulnerability with a CVSS score of 7.5 (HIGH). The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to e...
How severe is CVE-2013-4793?
CVE-2013-4793 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-4793?
Check the references section above for vendor advisories and patch information. Affected products include: Umbraco Umbraco Cms.