Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File Uploads
Description
Published by the National Vulnerability Database
Jun 3, 2025
Published to the GitHub Advisory Database
Jun 4, 2025
Reviewed
Jun 4, 2025
Impact
Via a manipulated API request it's possible to upload a file that doesn't adhere with the configured allowable file extensions.
Patches
Patched in 15.4.2 and 16.0.0.
Workarounds
None available.
References