Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-35240

Опубликовано: 28 мая 2024
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Umbraco Commerce is an open source dotnet ecommerce solution. In affected versions there exists a stored Cross-site scripting (XSS) issue which would enable attackers to inject malicious code into Print Functionality. This issue has been addressed in versions 12.1.4, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

EPSS

Процентиль: 50%
0.00268
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
больше 1 года назад

Umbraco Commerce vulnerable to Stored Cross-site Scripting on Print Functionality

EPSS

Процентиль: 50%
0.00268
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79