In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Files or Directories Accessible to External Parties vulnerabilities in an interactive lesson.
Start learningUpgrade Umbraco.Cms.Web.BackOffice to version 13.12.1 or higher.
Affected versions of this package are vulnerable to Files or Directories Accessible to External Parties in the dictionary import process. An attacker can enumerate the existence of arbitrary files on the server's filesystem and, in certain configurations, may expose the NTLM hash of the Windows account running the application by making predictable requests to temporary file paths and analyzing error responses. This is only exploitable if the attacker has an authorized backoffice account with access to the "Translations" section.
This vulnerability can be mitigated by restricting access to the "Translations" section to only trusted users.