CVE-2024-35240
Stored Cross-site Scripting on Print Functionality in Umbraco Commerce
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Umbraco Commerce is an open source dotnet ecommerce solution. In affected versions there exists a stored Cross-site scripting (XSS) issue which would enable attackers to inject malicious code into Print Functionality. This issue has been addressed in versions 12.1.4, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Umbraco Commerce es una solución de comercio electrónico dotnet de código abierto. En las versiones afectadas existe un problema de Cross-site scripting (XSS) almacenado que permitiría a los atacantes inyectar código malicioso en la funcionalidad de impresión. Este problema se solucionó en las versiones 12.1.4 y 10.0.5. Se recomienda a los usuarios que actualicen. No se conocen workarounds para esta vulnerabilidad.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-05-14 CVE Reserved
- 2024-05-28 CVE Published
- 2024-05-29 EPSS Updated
- 2024-08-19 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://docs.umbraco.com/umbraco-commerce/release-notes#id-13.0.0-december-13th-2023 | X_refsource_misc | |
https://github.com/umbraco/Umbraco.Commerce.Issues/security/advisories/GHSA-rpj9-xjwm-wr6w | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Umbraco Search vendor "Umbraco" | Umbraco.Commerce.Issues Search vendor "Umbraco" for product "Umbraco.Commerce.Issues" | >= 12.0.0 < 12.1.4 Search vendor "Umbraco" for product "Umbraco.Commerce.Issues" and version " >= 12.0.0 < 12.1.4" | en |
Affected
| ||||||
Umbraco Search vendor "Umbraco" | Umbraco.Commerce.Issues Search vendor "Umbraco" for product "Umbraco.Commerce.Issues" | < 10.0.5 Search vendor "Umbraco" for product "Umbraco.Commerce.Issues" and version " < 10.0.5" | en |
Affected
|