MEDIUM4.2
GHSA-c5g6-6xf7-qxp3
Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section
Quick fix
GHSA-c5g6-6xf7-qxp3 — Umbraco.Cms.StaticAssets: upgrade to the fixed version with the command below.
dotnet add package Umbraco.Cms.StaticAssets --version 14.3.1Details
### Impact This can be leveraged to gain access to higher-privilege endpoints, e.g. if you get a user with admin privileges to run the code, you can potentially elevate all users and grant them admin privileges or access protected content.
### Patches Will be patched in 14.3.1 and 15.0.0.
### Workarounds Ensure that access to the Dictionary section is only granted to trusted users.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/Umbraco.Cms.StaticAssets
Introduced in:
14.0.0Fixed in: 14.3.1Fix
dotnet add package Umbraco.Cms.StaticAssets --version 14.3.1npm/@umbraco-cms/backoffice
Introduced in:
14.0.0Fixed in: 14.3.1Fix
npm install @umbraco-cms/backoffice@14.3.1