Security Advisory

CVE-2012-10054

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-08-13 20:54:39
Last updated 2026-05-15 11:14:03
Assigner VulnCheck
CVSS score 9.3
State PUBLISHED

Description

Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the fileName parameter, attackers can write malicious ASPX scripts directly into the web-accessible /umbraco/ directory and execute them remotely.