CNNVD-202601-2763 Information

CNNVD ID

CNNVD-202601-2763

CVE-2025-68924

  • CNNVD Published: 2026-01-16

Description (Chinese)

Umbraco Forms是Umbraco公司的一款表单构建工具。 Umbraco Forms 8.13.16及之前版本存在安全漏洞,该漏洞源于经过身份验证的攻击者可提供恶意WSDL URL作为数据源,可能导致远程代码执行。

Description (English)

Umbraco Forms is a form construction tool for Umbraco. The Umbraco Forms 8.13.16 and previous versions had a security loophole, which stemmed from the fact that an identified assailant could provide malicious WSDL URL as a data source, which could lead to remote code implementation.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

Umbraco

Published

2026-01-16

Last Modified

2026-02-24

References

https://github.com/advisories/GHSA-vrgw-pc9c-qrrc https://our.umbraco.com/packages/developer-tools/umbraco-forms/ https://www.nuget.org/packages/UmbracoForms

Patch

https://releases.umbraco.com/

Share on: