Description
This can be leveraged to gain access to higher-privilege endpoints, e.g. if you get a user with admin privileges to run the code, you can potentially elevate all users and grant them admin privileges or access protected content.
Recommendation
Update the @umbraco-cms/backoffice package to the latest compatible version. Followings are version details:
- Affected version(s): >= 14.0.0, < 14.3.1
- Patched version(s): 14.3.1
References
Could your website be exposed too?
SmartScanner can check your website for Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Flowise and Flowise Chat Embed vulnerable to Stored Cross-site Scripting - CVE-2024-9148
- metascraper before v5.2.0 vulnerable to stored cross-site scripting - CVE-2018-3773
- Dash apps vulnerable to Cross-site Scripting - dash-core-components - CVE-2024-21485
- Dash apps vulnerable to Cross-site Scripting - CVE-2024-21485


