Description
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.1.0, a user with access to a specific part of the backoffice is able to inject HTML code into a form where it is not intended. Versions 8.18.10, 10.7.0, and 12.1.0 contain a patch for this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3328 | Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.1.0, a user with access to a specific part of the backoffice is able to inject HTML code into a form where it is not intended. Versions 8.18.10, 10.7.0, and 12.1.0 contain a patch for this issue. |
Github GHSA |
GHSA-xxc6-35r7-796w | Possible injection of HTML into user invite mails |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T17:46:56.603Z
Reserved: 2023-07-24T16:19:28.364Z
Link: CVE-2023-38694
No data.
Status : Modified
Published: 2023-12-12T17:15:07.917
Modified: 2024-11-21T08:14:04.243
Link: CVE-2023-38694
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA