« Volver al listado

CVE-2025-23041

Estado: AnalizadaMedia (5.3)—

Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short and long answer fields are validated only client-side, not server-side. This issue has been patched in versions 8.13.16, 10.5.7, 13.2.2, and 14.1.2. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-23041",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-23041",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-14T20:43:43.541022Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "umbraco",
          "product": "Umbraco.Forms.Issues",
          "versions": [
            {
              "status": "affected",
              "version": "< 8.13.16"
            },
            {
              "status": "affected",
              "version": ">= 10.0.0, < 10.5.7"
            },
            {
              "status": "affected",
              "version": ">= 11.0.0, < 13.2.2"
            },
            {
              "status": "affected",
              "version": ">= 14.0.0, < 14.1.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-01-14T19:15:44.713",
  "references": [
    {
      "url": "https://github.com/umbraco/Umbraco.Forms.Issues/security/advisories/GHSA-9v8m-qv22-f268",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short and long answer fields are validated only client-side, not server-side. This issue has been patched in versions 8.13.16, 10.5.7, 13.2.2, and 14.1.2. Users are advised to upgrade. There are no known workarounds for this issue."
    },
    {
      "lang": "es",
      "value": "Umbraco.Forms es un formulario web Framework escrito para el ecosistema NuGet. Los límites de caracteres configurados por los editores para los campos de respuesta cortos y largos se validan solo en el lado del cliente, no en el lado del servidor. Este problema se ha corregido en las versiones 8.13.16, 10.5.7, 13.2.2 y 14.1.2. Se recomienda a los usuarios que actualicen. No se conocen Workarounds para este problema."
    }
  ],
  "lastModified": "2026-06-17T08:51:38.523",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:umbraco:umbraco_forms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48883649-BC2F-48A4-9443-4A33CC340C81",
              "versionEndExcluding": "8.13.15"
            },
            {
              "criteria": "cpe:2.3:a:umbraco:umbraco_forms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09AA3AFC-F729-4C81-9C5C-ECB892172B56",
              "versionEndExcluding": "10.5.7",
              "versionStartIncluding": "10.0.0"
            },
            {
              "criteria": "cpe:2.3:a:umbraco:umbraco_forms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD6991DB-0A23-4DF2-BD2C-DCBF7C314609",
              "versionEndExcluding": "13.2.2",
              "versionStartIncluding": "13.0.0"
            },
            {
              "criteria": "cpe:2.3:a:umbraco:umbraco_forms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2FE59C05-6473-48D9-8858-7391EEECA852",
              "versionEndExcluding": "14.1.2",
              "versionStartIncluding": "14.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}