Description
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3294 | A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS. |
Github GHSA |
GHSA-95qr-67rx-9pgh | Umbraco CMS vulnerable to stored XSS |
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2020-59 |
|
History
No history.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-04T08:39:25.908Z
Reserved: 2020-01-06T00:00:00.000Z
Link: CVE-2020-5809
No data.
Status : Modified
Published: 2020-12-30T16:15:12.320
Modified: 2024-11-21T05:34:38.223
Link: CVE-2020-5809
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA