PT-2025-50229 · Umbraco · Umbraco
Publicado
2025-12-09
·
Atualizado
2026-01-02
·
CVE-2025-66625
CVSS v3.1
4.9
Média
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Umbraco versions 10.0.0 through 13.12.0
Description
Umbraco, an ASP.NET CMS, experiences an issue related to the unsafe handling and deletion of temporary files during the dictionary upload process. An attacker with backoffice access can leverage predictable requests to temporary file paths to enumerate the existence of arbitrary files on the server’s filesystem by observing differing error responses (HTTP 500 or 404). This does not permit reading or writing file contents. In specific configurations, incomplete cleanup of temporary upload files may reveal the NTLM hash of the Windows account running the Umbraco application.
Recommendations
Update to Umbraco version 13.12.1.
Exploit
Correção
Files Accessible to External Parties
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Umbraco