Intel

AIKIDO-2025-10287

Umbraco.Cms is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

15

Low Risk

This Affects:

dotnetUmbraco.Cms
9.3.0 - 15.3.1
Fixed in 15.4.0

TL;DR

Affected versions of this package are vulnerable to information disclosure due to improper access controls that allow back-office users without proper webhook permissions to access webhook logs due to insufficient access controls. Additionally, the application fails to properly validate file system paths, exposing resolved paths and potentially allowing directory traversal attacks. An attacker with back-office access, even without webhook privileges, can read sensitive webhook logs or access arbitrary files on the system. It leads to information disclosure or server compromise.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

Umbraco.Cms is vulnerable to Information Disclosure in versions 9.3.0 - 15.3.1.

How to fix this

Upgrade the Umbraco.Cms library to the patch version.