Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the fileName parameter, attackers can write malicious ASPX scripts directly into the web-accessible /umbraco/ directory and execute them remotely.
References
Configurations
History
No history.
Information
Published : 2025-08-13 21:15
Updated : 2025-09-19 17:02
NVD link : CVE-2012-10054
Mitre link : CVE-2012-10054
CVE.ORG link : CVE-2012-10054
JSON object : View
Products Affected
umbraco
- umbraco_cms
