VDB
Sign up
LOW2.7

GHSA-p572-p2rj-q5f4

Umbraco Forms components vulnerable to Stored Cross-site Scripting

Quick fix

GHSA-p572-p2rj-q5f4 — Umbraco.Forms: upgrade to the fixed version with the command below.

dotnet add package Umbraco.Forms --version 13.0.1

Details

### Impact Authenticated user that has access to edit Forms may inject unsafe code into Forms components.

### Patches Issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).

### References https://docs.umbraco.com/umbraco-forms/release-notes#id-13.0.1-january-16th-2024 https://docs.umbraco.com/umbraco-forms/v/12.forms.latest/release-notes#id-12.2.2-january-16th-2024 https://docs.umbraco.com/umbraco-forms/v/10.forms.latest/release-notes https://docs.umbraco.com/umbraco-forms/developer/configuration#editing-configuration-values

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/Umbraco.Forms
Introduced in: 13.0.0Fixed in: 13.0.1
Fixdotnet add package Umbraco.Forms --version 13.0.1
NuGet/Umbraco.Forms
Introduced in: 12.0.0Fixed in: 12.2.2
Fixdotnet add package Umbraco.Forms --version 12.2.2
NuGet/Umbraco.Forms
Introduced in: 10.0.0Fixed in: 10.5.3
Fixdotnet add package Umbraco.Forms --version 10.5.3
NuGet/Umbraco.Forms
Introduced in: 8.0.0Fixed in: 8.13.13
Fixdotnet add package Umbraco.Forms --version 8.13.13

References