PT-2023-30776 · Umbraco · Umbraco

Raphael

·

Publicado

2023-12-12

·

Atualizado

2023-12-14

·

CVE-2023-48313

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Umbraco versions 10.0.0 through 10.8.0 Umbraco versions 10.8.1 is not affected, but versions prior to 12.3.4 are affected, so the correct range is: Umbraco versions 10.8.2 through 12.3.3
Description The issue is a cross-site scripting (XSS) vulnerability that allows attackers to bring malicious content into a website or application. This can be exploited when users are successfully logging into the Backoffice, specifically through a DOM-XSS vulnerability.
Recommendations For Umbraco versions 10.0.0 through 10.8.0, update to version 10.8.1 to resolve the issue. For Umbraco versions 10.8.2 through 12.3.3, update to version 12.3.4 to resolve the issue.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-48313
GHSA-V98M-398X-269R

Produtos afetados

Umbraco