Vulnerabilities/

Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section

Severity:
Medium

Description

This can be leveraged to gain access to higher-privilege endpoints, e.g. if you get a user with admin privileges to run the code, you can potentially elevate all users and grant them admin privileges or access protected content.

Recommendation

Update the @umbraco-cms/backoffice package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@umbraco-cms/backoffice
Anything's wrong? Let us know Last updated on October 22, 2024