Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior to versions 15.2.3 and 14.3.3, allowing low-privilege, authenticated users to create and update data type information that should be restricted to users with access to the settings section. The issue is patched in versions 15.2.3 and 14.3.3. No known workarounds are available.
History

Tue, 11 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 15:45:00 +0000

Type Values Removed Values Added
Description Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior to versions 15.2.3 and 14.3.3, allowing low-privilege, authenticated users to create and update data type information that should be restricted to users with access to the settings section. The issue is patched in versions 15.2.3 and 14.3.3. No known workarounds are available.
Title Umbraco Allows Improper API Access Control to Low-Privilege Users to Data Type Functionality
Weaknesses CWE-285
CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-11T18:53:25.590Z

Reserved: 2025-03-03T15:10:34.078Z

Link: CVE-2025-27601

cve-icon Vulnrichment

Updated: 2025-03-11T18:53:21.827Z

cve-icon NVD

Status : Received

Published: 2025-03-11T16:15:17.943

Modified: 2025-03-11T16:15:17.943

Link: CVE-2025-27601

cve-icon Redhat

No data.