Логотип exploitDog
bind:CVE-2025-67288
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-67288

Количество 2

Количество 2

nvd логотип

CVE-2025-67288

около 2 месяцев назад

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself, a related issue to CVE-2023-49279.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-54mj-vcvj-q3v5

около 2 месяцев назад

Umbraco CMS has an arbitrary file upload vulnerability

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-67288

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself, a related issue to CVE-2023-49279.

CVSS3: 10
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-54mj-vcvj-q3v5

Umbraco CMS has an arbitrary file upload vulnerability

CVSS3: 10
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу