Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
Moderate severity
GitHub Reviewed
Published
May 21, 2024
in
umbraco/Umbraco-CMS
•
Updated Sep 24, 2024
Package
Affected versions
>= 8.0.0, < 8.18.13
>= 10.0.0, < 10.8.4
>= 12.0.0, < 12.3.7
>= 13.0.0, < 13.1.1
Patched versions
8.18.13
10.8.4
12.3.7
13.1.1
Description
Published by the National Vulnerability Database
May 21, 2024
Published to the GitHub Advisory Database
May 21, 2024
Reviewed
May 21, 2024
Last updated
Sep 24, 2024
Impact
Stored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application.
Affected versions
Umbraco CMS >= 8.00
Patches
This is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer
References