Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section
- Severity:
- Medium
Description
This can be leveraged to gain access to higher-privilege endpoints, e.g. if you get a user with admin privileges to run the code, you can potentially elevate all users and grant them admin privileges or access protected content.
Recommendation
Update the @umbraco-cms/backoffice package to the latest compatible version. Followings are version details:
- Affected version(s): >= 14.0.0, < 14.3.1
- Patched version(s): 14.3.1
References
Related Issues
- Flowise and Flowise Chat Embed vulnerable to Stored Cross-site Scripting - CVE-2024-9148
- metascraper before v5.2.0 vulnerable to stored cross-site scripting - CVE-2018-3773
- Dash apps vulnerable to Cross-site Scripting - dash-core-components - CVE-2024-21485
- Dash apps vulnerable to Cross-site Scripting - CVE-2024-21485
You might also like:
- Tags:
- npm
- @umbraco-cms/backoffice
Anything's wrong? Let us know Last updated on October 22, 2024


