Vulnerabilities > CVE-2020-29454 - Incorrect Authorization vulnerability in Umbraco CMS

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
umbraco
CWE-863

Summary

Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Applications.Settings access.

Common Weakness Enumeration (CWE)