5.4

CVE-2024-35239

Stored Cross-site Scripting on Components of Umbraco Forms

Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe code into Forms components. This issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to one of the patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
UmbracoUmbraco Forms Version < 8.13.13
UmbracoUmbraco Forms Version >= 9.0.0 < 10.5.3
UmbracoUmbraco Forms Version >= 11.0.0 < 12.2.2
UmbracoUmbraco Forms Version >= 13.0.0 < 13.0.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.258
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
security-advisories@github.com 2.7 1.2 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://docs.umbraco.com/umbraco-forms/developer/configuration#editing-configuration-values
Product
https://docs.umbraco.com/umbraco-forms/release-notes#id-13.0.1-january-16th-2024
Release Notes
https://docs.umbraco.com/umbraco-forms/v/10.forms.latest/release-notes
Release Notes
https://docs.umbraco.com/umbraco-forms/v/12.forms.latest/release-notes#id-12.2.2-january-16th-2024
Release Notes
https://github.com/umbraco/Umbraco.Forms.Issues/security/advisories/GHSA-p572-p2rj-q5f4
Vendor Advisory