High severityNVD Advisory· Published Apr 8, 2025· Updated Apr 9, 2025
Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users
CVE-2025-32017
Description
Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is patched in 14.3.4 and 15.3.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Umbraco.CmsNuGet | >= 14.0.0--preview004, < 14.3.4 | 14.3.4 |
Umbraco.CmsNuGet | >= 15.0.0-rc1, < 15.3.1 | 15.3.1 |
Affected products
2- Range: >= 14.0.0--preview004, < 14.3.4
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-q62r-8ppj-xvf4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-32017ghsaADVISORY
- github.com/umbraco/Umbraco-CMS/commit/06a2a500b358ce15b1e228391eb60bd517c6e833ghsax_refsource_MISCWEB
- github.com/umbraco/Umbraco-CMS/commit/d3c1443b14b1076faf13d1bcecc42860fdf5fad8ghsax_refsource_MISCWEB
- github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-q62r-8ppj-xvf4ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.