PT-2024-26404 · Umbraco · Umbraco Commerce

Raphaelcssilva

·

Published

2024-05-28

·

Updated

2024-05-29

·

CVE-2024-35240

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Umbraco Commerce versions prior to 10.0.5 Umbraco Commerce versions prior to 12.1.4
Description The issue is a stored Cross-site scripting (XSS) problem that allows attackers to inject malicious code into the Print Functionality. This enables attackers to execute malicious scripts, potentially leading to unauthorized access or data theft. Users are advised to upgrade to address this issue.
Recommendations For versions prior to 10.0.5, upgrade to version 10.0.5 or later. For versions prior to 12.1.4, upgrade to version 12.1.4 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-35240
GHSA-RPJ9-XJWM-WR6W

Affected Products

Umbraco Commerce