PT-2025-23653 · Umbraco · Umbraco

00Mpal00Mpa

·

Published

2025-06-03

·

Updated

2025-06-04

·

CVE-2025-48953

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Umbraco versions 14.0.0 through 15.4.1
Description The issue allows uploading a file that does not adhere to the configured allowable file extensions via a manipulated API request. The problem is resolved in versions 15.4.2 and 16.0.0.
Recommendations For versions 14.0.0 through 15.4.1, update to version 15.4.2 or 16.0.0 to resolve the issue. As a temporary workaround, consider restricting API requests to prevent unauthorized file uploads until a patch is applied.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-48953
GHSA-FR6R-P8HV-X3C4

Affected Products

Umbraco