Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 NuGet

Umbraco Allows User Enumeration Feasible Based On Management API Timing and Response Codes

GHSA-hmg4-wwm5-p999 · CVE-2025-24011

Published · Modified

Description

Impact

Based on an analysis of response codes and timing of Umbraco 14+ management API responses, it's possible to determine whether an account exists.

Patches

Patched in 14.3.2 and 15.1.2.

Workarounds

None available.

Ready to move

Start Securing

Free, no credit card | First findings in minutes