VDB
Sign up
MEDIUM4.2

GHSA-gvpc-3pj6-4m9w

Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane

Quick fix

GHSA-gvpc-3pj6-4m9w — UmbracoCms.Core: upgrade to the fixed version with the command below.

dotnet add package UmbracoCms.Core --version 8.18.13

Details

### Impact Stored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application.

### Affected versions Umbraco CMS >= 8.00

### Patches This is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/UmbracoCms.Core
Introduced in: 8.0.0Fixed in: 8.18.13
Fixdotnet add package UmbracoCms.Core --version 8.18.13
NuGet/UmbracoCms.Core
Introduced in: 10.0.0Fixed in: 10.8.4
Fixdotnet add package UmbracoCms.Core --version 10.8.4
NuGet/UmbracoCms.Core
Introduced in: 12.0.0Fixed in: 12.3.7
Fixdotnet add package UmbracoCms.Core --version 12.3.7
NuGet/UmbracoCms.Core
Introduced in: 13.0.0Fixed in: 13.1.1
Fixdotnet add package UmbracoCms.Core --version 13.1.1

References