← Back

CVE-2024-35218

nvd nist
Published: May 21, 2024Modified: Feb 12, 2025

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: NVD

Description

Umbraco CMS is an ASP.NET CMS used by more than 730.000 websites. Stored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. This vulnerability has been patched in version(s) 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer.

Affected (4)

Products: Umbraco: Umbraco Cms
1 product
Umbraco Cms
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Umbraco
From 10.0.0 to 10.8.4
From 12.0.0 to 12.3.7
From 13.0.0 to 13.1.1
From 8.0.0 to 8.18.13

Timeline

No history available yet.