Vulnerability Details CVE-2024-43376
Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This vulnerability is fixed in 14.1.2.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.5%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2024-43376
-
cpe:2.3:a:umbraco:umbraco_cms:14.0.0
-
cpe:2.3:a:umbraco:umbraco_cms:14.1.0
-
cpe:2.3:a:umbraco:umbraco_cms:14.1.1