PT-2025-4787 · Umbraco · Umbraco Forms

Rgv2Zwxvcgvy

·

Publicado

2025-01-14

·

Atualizado

2025-01-15

·

CVE-2025-23041

CVSS v3.1

5.8

Média

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Umbraco.Forms versions prior to 8.13.16 Umbraco.Forms versions prior to 10.5.7 Umbraco.Forms versions prior to 13.2.2 Umbraco.Forms versions prior to 14.1.2
Description The character limits configured by editors for short and long answer fields in Umbraco.Forms are validated only on the client-side, not on the server-side. This issue has been corrected in versions 8.13.16, 10.5.7, 13.2.2, and 14.1.2. Users are advised to upgrade to one of these versions to resolve the issue.
Recommendations For versions prior to 8.13.16, update to version 8.13.16 or later. For versions prior to 10.5.7, update to version 10.5.7 or later. For versions prior to 13.2.2, update to version 13.2.2 or later. For versions prior to 14.1.2, update to version 14.1.2 or later.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-23041
GHSA-9V8M-QV22-F268

Produtos afetados

Umbraco Forms