Логотип exploitDog
bind:CVE-2023-38694
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-38694

Количество 2

Количество 2

nvd логотип

CVE-2023-38694

больше 1 года назад

Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.1.0, a user with access to a specific part of the backoffice is able to inject HTML code into a form where it is not intended. Versions 8.18.10, 10.7.0, and 12.1.0 contain a patch for this issue.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xxc6-35r7-796w

больше 1 года назад

Possible injection of HTML into user invite mails

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-38694

Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.1.0, a user with access to a specific part of the backoffice is able to inject HTML code into a form where it is not intended. Versions 8.18.10, 10.7.0, and 12.1.0 contain a patch for this issue.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxc6-35r7-796w

Possible injection of HTML into user invite mails

0%
Низкий
больше 1 года назад

Уязвимостей на страницу