Vulnerability Description
Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:script in an xsltSelection to developer/Xslt/xsltVisualize.aspx.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Umbraco | Umbraco Cms | >= 4.11.8, <= 7.15.10 |
Related Weaknesses (CWE)
References
- https://0xdf.gitlab.io/2020/09/05/htb-remote.htmlExploitThird Party Advisory
- https://github.com/Ickarah/CVE-2019-25137-Version-ResearchExploitThird Party Advisory
- https://github.com/noraj/Umbraco-RCEExploitThird Party Advisory
- https://www.exploit-db.com/exploits/46153ExploitThird Party AdvisoryVDB Entry
- https://0xdf.gitlab.io/2020/09/05/htb-remote.htmlExploitThird Party Advisory
- https://github.com/Ickarah/CVE-2019-25137-Version-ResearchExploitThird Party Advisory
- https://github.com/noraj/Umbraco-RCEExploitThird Party Advisory
- https://www.exploit-db.com/exploits/46153ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2019-25137?
CVE-2019-25137 is a vulnerability with a CVSS score of 7.2 (HIGH). Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:script in an xsltSelection to developer/Xslt/xsltVisualize.aspx.
How severe is CVE-2019-25137?
CVE-2019-25137 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25137?
Check the references section above for vendor advisories and patch information. Affected products include: Umbraco Umbraco Cms.