PT-2025-10787 · Umbraco · Umbraco

Hazemeldoc

·

Published

2025-03-11

·

Updated

2025-03-11

·

CVE-2025-27602

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Umbraco versions prior to 10.8.9 Umbraco versions prior to 13.7.1
Description: The issue allows authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to, via manipulation of backoffice API URLs.
Recommendations: For versions prior to 10.8.9, update to version 10.8.9 or later. For versions prior to 13.7.1, update to version 13.7.1 or later.

Exploit

Fix

LPE

Incorrect Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27602
GHSA-WX5H-WQFQ-V698

Affected Products

Umbraco