Description
Umbraco is an ASP.NET content management system (CMS). Starting in 10.0.0 and prior to versions 10.8.1 and 12.3.4, Umbraco contains a cross-site scripting (XSS) vulnerability enabling attackers to bring malicious content into a website or application. Versions 10.8.1 and 12.3.4 contain a patch for this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3302 | Umbraco is an ASP.NET content management system (CMS). Starting in 10.0.0 and prior to versions 10.8.1 and 12.3.4, Umbraco contains a cross-site scripting (XSS) vulnerability enabling attackers to bring malicious content into a website or application. Versions 10.8.1 and 12.3.4 contain a patch for this issue. |
Github GHSA |
GHSA-v98m-398x-269r | DOM-XSS on Backoffice login screen. |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-28T14:45:34.143Z
Reserved: 2023-11-14T17:41:15.573Z
Link: CVE-2023-48313
Updated: 2024-08-02T21:23:39.496Z
Status : Modified
Published: 2023-12-12T18:15:22.933
Modified: 2024-11-21T08:31:28.180
Link: CVE-2023-48313
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA