PT-2020-18726 · Umbraco+1 · Umbraco Cms+1

Evan Grant

·

Published

2020-12-30

·

Updated

2022-05-24

·

CVE-2020-5809

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Umbraco CMS versions prior to 8.9.2
Description A stored XSS issue exists, allowing an authenticated user to inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor. This is possible because TinyMCE is configured to allow iframes by default in Umbraco CMS.
Recommendations For Umbraco CMS versions prior to 8.9.2, update to version 8.9.2 or later to resolve the issue. As a temporary workaround, consider disabling the use of iframes in the TinyMCE rich-text editor until a patch is available. Restrict access to the TinyMCE editor to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5809
GHSA-95QR-67RX-9PGH

Affected Products

Tinymce
Umbraco Cms