Description
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3294 | A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS. |
Github GHSA |
GHSA-95qr-67rx-9pgh | Umbraco CMS vulnerable to stored XSS |
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2020-59 |
|
History
No history.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-04T08:39:25.908Z
Reserved: 2020-01-06T00:00:00.000Z
Link: CVE-2020-5809
No data.
Status : Modified
Published: 2020-12-30T16:15:12.320
Modified: 2024-11-21T05:34:38.223
Link: CVE-2020-5809
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA