Umbraco possible user enumeration
Description
Published to the GitHub Advisory Database
Mar 20, 2024
Reviewed
Mar 20, 2024
Published by the National Vulnerability Database
Mar 20, 2024
Last updated
Apr 12, 2024
Impact
A user enumeration attack is possible.
Affected versions
Umbraco 10 with access to the native login screen
Patches
This is fixed in 10.8.5
Workarounds
Disabling the native login screen, by exclusively use external logins.
References