Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users
Vulnerability Description
Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is patched in 14.3.4 and 15.3.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-32017
Credits & Attribution
No credits recorded in the NVD database.
References
More from umbraco
View All →Affected Vendor
umbraco
View all reports →