Vulnerabilities/

XSS/HTML Injection Vulnerability in Umbraco Backoffice Components

Severity:
Medium

Description

Authenticated users are able to exploit an XSS vulnerability when viewing certain localized backoffice components.

Recommendation

Update the @umbraco-cms/backoffice package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@umbraco-cms/backoffice
Anything's wrong? Let us know Last updated on January 21, 2025