Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
Moderate severity
GitHub Reviewed
Published
May 21, 2024
in
umbraco/Umbraco-CMS
•
Updated Feb 12, 2025
Package
Affected versions
>= 8.0.0, < 8.18.13
>= 10.0.0, < 10.8.4
>= 12.0.0, < 12.3.7
>= 13.0.0, < 13.1.1
Patched versions
8.18.13
10.8.4
12.3.7
13.1.1
Description
Published by the National Vulnerability Database
May 21, 2024
Published to the GitHub Advisory Database
May 21, 2024
Reviewed
May 21, 2024
Last updated
Feb 12, 2025
Impact
Stored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application.
Affected versions
Umbraco CMS >= 8.00
Patches
This is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer
References