Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe code into Forms components. This issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to one of the patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-05-28T20:15:28.512Z
Updated: 2024-08-02T03:07:46.872Z
Reserved: 2024-05-14T15:39:41.786Z
Link: CVE-2024-35239
Vulnrichment
Updated: 2024-06-05T20:42:35.320Z
NVD
Status : Awaiting Analysis
Published: 2024-05-28T21:16:31.163
Modified: 2024-05-29T13:02:09.280
Link: CVE-2024-35239
Redhat
No data.