PT-2025-10787 · Umbraco · Umbraco
Hazemeldoc
·
Published
2025-03-11
·
Updated
2025-03-11
·
CVE-2025-27602
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Umbraco versions prior to 10.8.9
Umbraco versions prior to 13.7.1
Description:
The issue allows authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to, via manipulation of backoffice API URLs.
Recommendations:
For versions prior to 10.8.9, update to version 10.8.9 or later.
For versions prior to 13.7.1, update to version 13.7.1 or later.
Exploit
Fix
LPE
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Umbraco