2.7
CVE-2024-35239
- EPSS 0.34%
- Veröffentlicht 28.05.2024 21:16:31
- Zuletzt bearbeitet 21.11.2024 09:20:00
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe code into Forms components. This issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to one of the patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerumbraco
≫
Produkt
Umbraco.Forms.Issues
Version
>= 13.0.0, < 13.0.1
Status
affected
Version
>= 12.0.0, < 12.2.2
Status
affected
Version
>= 10.0.0, < 10.5.3
Status
affected
Version
< 8.13.13
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.562 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 2.7 | 1.2 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.