CVE-2025-24012

CVSS 3.1 Score 4.6 of 10 (medium)

Details

Published Jan 21, 2025
CWE ID 79

Summary

CVE-2025-24012 is a cross-site scripting (XSS) vulnerability affecting versions 14.0.0 and prior to 14.3.2 and 15.1.2 of Umbraco, a free and open-source .NET content management system. Authenticated users can exploit this issue by injecting malicious scripts into certain localized backoffice components, posing a security risk. Versions 14.3.2 and 15.1.2 have been released with necessary patches to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share