CVE-2025-24011
Last modified
CVE-2025-24011 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, it's possible to determine whether an account exists based on an analysis of response codes and timing of Umbraco management API responses. EPSS estimates a 1.45% chance of exploitation in the next 30 days.
Description
Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, it's possible to determine whether an account exists based on an analysis of response codes and timing of Umbraco management API responses. Versions 14.3.2 and 15.1.2 contain a patch. No known workarounds are available.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Umbraco | Umbraco Cms | >= 14.0.0, < 14.3.2 |
| Umbraco | Umbraco Cms | >= 15.0.0, < 15.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-24011?
How severe is CVE-2025-24011?
How do I fix CVE-2025-24011?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-24006A low privileged local attacker can leverage insecure permis…7.8
- CVE-2025-24007A vulnerability has been identified in SIRIUS 3RK3 Modular S…8.7
- CVE-2025-24008A vulnerability has been identified in SIRIUS 3RK3 Modular S…8.7
- CVE-2025-24009A vulnerability has been identified in SIRIUS 3RK3 Modular S…8.2
- CVE-2025-2401Buffer overflow vulnerability in Immunity Debugger affecting…5.4
- CVE-2025-24010Vite is a frontend tooling framework for javascript. Vite al…6.5
- CVE-2025-24012Umbraco is a free and open source .NET content management sy…5.4
- CVE-2025-24013CodeIgniter is a PHP full-stack web framework. Prior to 4.5.…5.3
- CVE-2025-24014Vim is an open source, command line text editor. A segmentat…5.5
- CVE-2025-24015Deno is a JavaScript, TypeScript, and WebAssembly runtime. V…5.3
- CVE-2025-24016Wazuh is a free and open source platform used for threat pre…9.9
- CVE-2025-24017YesWiki is a wiki system written in PHP. Versions up to and …6.1
Are you affected by CVE-2025-24011?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
