CVE-2012-10054 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRSc…
Critical CVSS: 9.3

CVE-2012-10054

Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the fileName parameter, attackers can write malicious ASPX scripts directly into the web-accessible /umbraco/ directory and execute them remotely.
Vendor
Umbraco
Product
Umbraco Cms
CWE
CWE-22
Yayın Tarihi
2025-08-13 21:15:29
Güncelleme
2025-09-19 17:02:51
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar