Description
Umbraco, a free and open source .NET content management system, has a cross-site scripting vulnerability starting in version 14.0.0 and prior to versions 14.3.1 and 15.0.0. This can be leveraged to gain access to higher-privilege endpoints, e.g. if you get a user with admin privileges to run the code, you can potentially elevate all users and grant them admin privileges or access protected content. Versions 14.3.1 and 15.0.0 contain a patch. As a workaround, ensure that access to the Dictionary section is only granted to trusted users.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3012 | Umbraco, a free and open source .NET content management system, has a cross-site scripting vulnerability starting in version 14.0.0 and prior to versions 14.3.1 and 15.0.0. This can be leveraged to gain access to higher-privilege endpoints, e.g. if you get a user with admin privileges to run the code, you can potentially elevate all users and grant them admin privileges or access protected content. Versions 14.3.1 and 15.0.0 contain a patch. As a workaround, ensure that access to the Dictionary section is only granted to trusted users. |
Github GHSA |
GHSA-c5g6-6xf7-qxp3 | Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section |
References
History
Tue, 22 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Umbraco
Umbraco umbraco Cms |
|
| CPEs | cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Umbraco
Umbraco umbraco Cms |
|
| Metrics |
ssvc
|
Tue, 22 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Umbraco, a free and open source .NET content management system, has a cross-site scripting vulnerability starting in version 14.0.0 and prior to versions 14.3.1 and 15.0.0. This can be leveraged to gain access to higher-privilege endpoints, e.g. if you get a user with admin privileges to run the code, you can potentially elevate all users and grant them admin privileges or access protected content. Versions 14.3.1 and 15.0.0 contain a patch. As a workaround, ensure that access to the Dictionary section is only granted to trusted users. | |
| Title | Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-22T15:55:27.159Z
Reserved: 2024-10-03T14:06:12.638Z
Link: CVE-2024-47819
Updated: 2024-10-22T15:55:06.356Z
Status : Analyzed
Published: 2024-10-22T16:15:07.500
Modified: 2024-10-25T14:24:36.823
Link: CVE-2024-47819
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA