VDB
Sign up
MEDIUM4.2

GHSA-c5g6-6xf7-qxp3

Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section

Quick fix

GHSA-c5g6-6xf7-qxp3 — Umbraco.Cms.StaticAssets: upgrade to the fixed version with the command below.

dotnet add package Umbraco.Cms.StaticAssets --version 14.3.1

Details

### Impact This can be leveraged to gain access to higher-privilege endpoints, e.g. if you get a user with admin privileges to run the code, you can potentially elevate all users and grant them admin privileges or access protected content.

### Patches Will be patched in 14.3.1 and 15.0.0.

### Workarounds Ensure that access to the Dictionary section is only granted to trusted users.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/Umbraco.Cms.StaticAssets
Introduced in: 14.0.0Fixed in: 14.3.1
Fixdotnet add package Umbraco.Cms.StaticAssets --version 14.3.1
npm/@umbraco-cms/backoffice
Introduced in: 14.0.0Fixed in: 14.3.1
Fixnpm install @umbraco-cms/backoffice@14.3.1

References