PT-2025-10785 · Umbraco · Umbraco
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Umbraco versions prior to 15.2.3
Umbraco versions prior to 14.3.3
Description:
An improper API access control issue has been identified in Umbraco's API management package, allowing low-privilege, authenticated users to create and update data type information that should be restricted to users with access to the settings section.
Recommendations:
For versions prior to 15.2.3, update to version 15.2.3 or later.
For versions prior to 14.3.3, update to version 14.3.3 or later.
Exploit
Fix
DoS
Improper Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Umbraco