Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hfv2-pf68-m33x | Umbraco Vulnerable to Improper File Access and Credential Exposure in Dictionary Import Functionality |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 12 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows Umbraco Umbraco umbraco Umbraco umbraco Cms |
|
| Vendors & Products |
Microsoft
Microsoft windows Umbraco Umbraco umbraco Umbraco umbraco Cms |
Tue, 09 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, during the dictionary upload process an attacker with access to the backoffice can trigger predictable requests to temporary file paths. The application’s error responses (HTTP 500 when a file exists, 404 when it does not) allow the attacker to enumerate the existence of arbitrary files on the server’s filesystem. This vulnerability does not allow reading or writing file contents. In certain configurations, incomplete clean-up of temporary upload files may additionally expose the NTLM hash of the Windows account running the Umbraco application. This issue is fixed in version 13.12.1. | |
| Title | Umbraco Vulnerable to Improper File Access and Credential Exposure through Dictionary Import Functionality | |
| Weaknesses | CWE-200 CWE-377 CWE-552 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-12T20:33:09.177Z
Reserved: 2025-12-05T15:18:02.789Z
Link: CVE-2025-66625
Updated: 2025-12-12T20:33:05.894Z
Status : Awaiting Analysis
Published: 2025-12-09T20:15:55.320
Modified: 2025-12-12T15:19:07.567
Link: CVE-2025-66625
No data.
OpenCVE Enrichment
Updated: 2025-12-10T17:49:00Z
Github GHSA