PT-2025-4787 · Umbraco · Umbraco Forms

Rgv2Zwxvcgvy

·

Published

2025-01-14

·

Updated

2025-01-15

·

CVE-2025-23041

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Umbraco.Forms versions prior to 8.13.16 Umbraco.Forms versions prior to 10.5.7 Umbraco.Forms versions prior to 13.2.2 Umbraco.Forms versions prior to 14.1.2
Description The character limits configured by editors for short and long answer fields in Umbraco.Forms are validated only on the client-side, not on the server-side. This issue has been corrected in versions 8.13.16, 10.5.7, 13.2.2, and 14.1.2. Users are advised to upgrade to one of these versions to resolve the issue.
Recommendations For versions prior to 8.13.16, update to version 8.13.16 or later. For versions prior to 10.5.7, update to version 10.5.7 or later. For versions prior to 13.2.2, update to version 13.2.2 or later. For versions prior to 14.1.2, update to version 14.1.2 or later.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-23041
GHSA-9V8M-QV22-F268

Affected Products

Umbraco Forms