๐Ÿ” CVE Alert

CVE-2012-10054

UNKNOWN 0.0

Umbraco CMS < 4.7.1 codeEditorSave.asmx RCE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the fileName parameter, attackers can write malicious ASPX scripts directly into the web-accessible /umbraco/ directory and execute them remotely.

CWE CWE-434 CWE-22
Vendor umbraco
Product cms
Published Aug 13, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for umbraco cms

Be the first to know when new unknown vulnerabilities affecting umbraco cms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Umbraco / CMS
* < 4.7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
raw.githubusercontent.com: https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/http/umbraco_upload_aspx.rb exploit-db.com: https://www.exploit-db.com/exploits/19671 web.archive.org: https://web.archive.org/web/20120707033729/http://blog.gdssecurity.com/labs/2012/7/3/find-bugs-faster-with-a-webmatrix-local-reference-instance.html github.com: https://github.com/umbraco/Umbraco-CMS web.archive.org: https://web.archive.org/web/20111017174609/http://umbraco.codeplex.com/releases/view/73692 vulncheck.com: https://www.vulncheck.com/advisories/umbraco-cms-rce

Credits

Toby Clarke