CVE-2024-35239
Stored Cross-site Scripting on Components of Umbraco Forms
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe code into Forms components. This issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to one of the patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).
Umbraco Commerce es una solución de formularios web dotnet de código abierto. En las versiones afectadas, un usuario autenticado que tiene acceso para editar formularios puede inyectar código no seguro en los componentes de Forms. Este problema se puede mitigar configurando TitleAndDescription:AllowUnsafeHtmlRendering después de actualizar a una de las versiones parcheadas (13.0.1, 12.2.2, 10.5.3, 8.13.13).
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-05-14 CVE Reserved
- 2024-05-28 CVE Published
- 2024-05-29 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://docs.umbraco.com/umbraco-forms/developer/configuration#editing-configuration-values | X_refsource_misc | |
https://docs.umbraco.com/umbraco-forms/release-notes#id-13.0.1-january-16th-2024 | X_refsource_misc | |
https://docs.umbraco.com/umbraco-forms/v/10.forms.latest/release-notes | X_refsource_misc | |
https://docs.umbraco.com/umbraco-forms/v/12.forms.latest/release-notes#id-12.2.2-january-16th-2024 | X_refsource_misc | |
https://github.com/umbraco/Umbraco.Forms.Issues/security/advisories/GHSA-p572-p2rj-q5f4 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Umbraco Search vendor "Umbraco" | Umbraco.Forms.Issues Search vendor "Umbraco" for product "Umbraco.Forms.Issues" | >= 13.0.0 < 13.0.1 Search vendor "Umbraco" for product "Umbraco.Forms.Issues" and version " >= 13.0.0 < 13.0.1" | en |
Affected
| ||||||
Umbraco Search vendor "Umbraco" | Umbraco.Forms.Issues Search vendor "Umbraco" for product "Umbraco.Forms.Issues" | >= 12.0.0 < 12.2.2 Search vendor "Umbraco" for product "Umbraco.Forms.Issues" and version " >= 12.0.0 < 12.2.2" | en |
Affected
| ||||||
Umbraco Search vendor "Umbraco" | Umbraco.Forms.Issues Search vendor "Umbraco" for product "Umbraco.Forms.Issues" | >= 10.0.0 < 10.5.3 Search vendor "Umbraco" for product "Umbraco.Forms.Issues" and version " >= 10.0.0 < 10.5.3" | en |
Affected
| ||||||
Umbraco Search vendor "Umbraco" | Umbraco.Forms.Issues Search vendor "Umbraco" for product "Umbraco.Forms.Issues" | < 8.13.13 Search vendor "Umbraco" for product "Umbraco.Forms.Issues" and version " < 8.13.13" | en |
Affected
|