Описание
XSS/HTML Injection Vulnerability in Umbraco Backoffice Components
Impact
Authenticated users are able to exploit an XSS vulnerability when viewing certain localized backoffice components.
Patches
Will be patched in 14.3.2 and 15.1.2.
Note: This issue was reported by Pratik Patil from NetSPI @Nexusss-ppatil
Пакеты
Umbraco.Cms.StaticAssets
>= 14.0.0, < 14.3.2
14.3.2
Umbraco.Cms.StaticAssets
>= 15.0.0, < 15.1.2
15.1.2
@umbraco-cms/backoffice
>= 14.0.0, < 14.3.2
14.3.2
@umbraco-cms/backoffice
>= 15.0.0, < 15.1.2
15.1.2
Связанные уязвимости
Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, authenticated users are able to exploit a cross-site scripting vulnerability when viewing certain localized backoffice components. Versions 14.3.2 and 15.1.2 contain a patch.