We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-32017

Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users



Description

Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is patched in 14.3.4 and 15.3.1.

Reserved 2025-04-01 | Published 2025-04-08 | Updated 2025-04-09 | Assigner GitHub_M


HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-23: Relative Path Traversal

Product status

>= 14.0.0--preview004, < 14.3.4
affected

>= 15.0.0-rc1, < 15.3.1
affected

References

github.com/...co-CMS/security/advisories/GHSA-q62r-8ppj-xvf4

github.com/...ommit/06a2a500b358ce15b1e228391eb60bd517c6e833

github.com/...ommit/d3c1443b14b1076faf13d1bcecc42860fdf5fad8

cve.org (CVE-2025-32017)

nvd.nist.gov (CVE-2025-32017)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-32017

Support options

Helpdesk Chat, Email, Knowledgebase