Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-572q-86rr-5vgq

Опубликовано: 22 янв. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Withdrawn Advisory: Umbraco Rich Text Display allows Cross-Site Scripting

Withdrawn Advisory

This advisory has been withdrawn because the issue is a documented security. This link is maintained to preserve external references. For more information, see https://github.com/github/advisory-database/pull/5270.

Original Advisory

A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Пакеты

Наименование

Umbraco.Cms.Infrastructure

nuget
Затронутые версииВерсия исправления

< 15.0.0

15.0.0

EPSS

Процентиль: 41%
0.00189
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 года назад

A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: This has been disputed by the vendor since this potential attack is only possible via authenticated users who have been manually allowed access to the CMS. There was a deliberate decision made not to apply HTML sanitization at the product level.

CVSS3: 6.5
fstec
около 1 года назад

Уязвимость системы управления контентом Umbraco CMS, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)

EPSS

Процентиль: 41%
0.00189
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79