First published: Tue Jan 21 2025(Updated: )
### Impact Based on an analysis of response codes and timing of Umbraco 14+ management API responses, it's possible to determine whether an account exists. ### Patches Will be patched in 14.3.2 and 15.1.2. ### Workarounds None available.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Umbraco.Cms | >=15.0.0<15.1.2 | 15.1.2 |
nuget/Umbraco.Cms | >=14.0.0<14.3.2 | 14.3.2 |
Umbraco CMS | >14.0.0<14.3.2>15.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24011 has a moderate severity level as it exposes account existence through response codes and timing.
To fix CVE-2025-24011, update Umbraco to version 14.3.2 or later, or to version 15.1.2.
CVE-2025-24011 affects Umbraco versions between 14.0.0 and 14.3.1 and 15.0.0 and 15.1.1.
There are currently no available workarounds for CVE-2025-24011.
CVE-2025-24011 is an information disclosure vulnerability that allows for the enumeration of user accounts.