Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1, via manipulation of backoffice API URLs, it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. The issue is patched in versions 10.8.9 and 13.7.1. No known workarounds are available.
History

Tue, 11 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 15:45:00 +0000

Type Values Removed Values Added
Description Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1, via manipulation of backoffice API URLs, it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. The issue is patched in versions 10.8.9 and 13.7.1. No known workarounds are available.
Title Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
Weaknesses CWE-285
CWE-863
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-11T18:52:56.698Z

Reserved: 2025-03-03T15:10:34.078Z

Link: CVE-2025-27602

cve-icon Vulnrichment

Updated: 2025-03-11T18:52:52.125Z

cve-icon NVD

Status : Received

Published: 2025-03-11T16:15:18.100

Modified: 2025-03-11T16:15:18.100

Link: CVE-2025-27602

cve-icon Redhat

No data.