{"id":"GHSA-q62r-8ppj-xvf4","summary":"Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users","details":"### Impact\nAuthenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location.\n\n### Patches\nThe issue affects Umbraco 14+ and is patched in 14.3.4 and 15.3.1.\n\n### Workarounds\nUmbraco supports the configuration of [allowed](https://docs.umbraco.com/umbraco-cms/reference/configuration/contentsettings#allowed-upload-file-extensions) and [disallowed file extensions](https://docs.umbraco.com/umbraco-cms/reference/configuration/contentsettings#disallowed-upload-file-extensions).  Using these options to allow only necessary file extensions significantly reduces the scope of the vulnerability.","aliases":["CVE-2025-32017"],"modified":"2025-04-09T17:32:13.162092Z","published":"2025-04-09T12:49:38Z","database_specific":{"cwe_ids":["CWE-22","CWE-23"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-04-09T12:49:38Z","nvd_published_at":"2025-04-08T16:15:27Z"},"references":[{"type":"WEB","url":"https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-q62r-8ppj-xvf4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32017"},{"type":"WEB","url":"https://github.com/umbraco/Umbraco-CMS/commit/06a2a500b358ce15b1e228391eb60bd517c6e833"},{"type":"WEB","url":"https://github.com/umbraco/Umbraco-CMS/commit/d3c1443b14b1076faf13d1bcecc42860fdf5fad8"},{"type":"PACKAGE","url":"https://github.com/umbraco/Umbraco-CMS"}],"affected":[{"package":{"name":"Umbraco.Cms","ecosystem":"NuGet","purl":"pkg:nuget/Umbraco.Cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14.0.0--preview004"},{"fixed":"14.3.4"}]}],"versions":["14.0.0","14.0.0-rc1","14.0.0-rc2","14.0.0-rc3","14.0.0-rc4","14.0.0-rc5","14.1.0","14.1.0-rc","14.1.0-rc2","14.1.1","14.1.2","14.2.0","14.2.0-rc","14.2.0-rc2","14.2.0-rc3","14.3.0","14.3.0-rc","14.3.1","14.3.2","14.3.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-q62r-8ppj-xvf4/GHSA-q62r-8ppj-xvf4.json"}},{"package":{"name":"Umbraco.Cms","ecosystem":"NuGet","purl":"pkg:nuget/Umbraco.Cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15.0.0-rc1"},{"fixed":"15.3.1"}]}],"versions":["15.0.0","15.0.0-rc1","15.0.0-rc2","15.0.0-rc3","15.0.0-rc4","15.1.0","15.1.0-rc","15.1.0-rc2","15.1.1","15.1.2","15.2.0","15.2.0-rc","15.2.1","15.2.2","15.2.3","15.3.0","15.3.0-rc","15.3.0-rc2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-q62r-8ppj-xvf4/GHSA-q62r-8ppj-xvf4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}