GHSA-p572-p2rj-q5f4
Umbraco Forms components vulnerable to Stored Cross-site Scripting
Quick fix
GHSA-p572-p2rj-q5f4 — Umbraco.Forms: upgrade to the fixed version with the command below.
dotnet add package Umbraco.Forms --version 13.0.1Details
### Impact Authenticated user that has access to edit Forms may inject unsafe code into Forms components.
### Patches Issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).
### References https://docs.umbraco.com/umbraco-forms/release-notes#id-13.0.1-january-16th-2024 https://docs.umbraco.com/umbraco-forms/v/12.forms.latest/release-notes#id-12.2.2-january-16th-2024 https://docs.umbraco.com/umbraco-forms/v/10.forms.latest/release-notes https://docs.umbraco.com/umbraco-forms/developer/configuration#editing-configuration-values
Are you affected?
Enter the version of the package you're using.
Affected packages
13.0.0Fixed in: 13.0.1dotnet add package Umbraco.Forms --version 13.0.112.0.0Fixed in: 12.2.2dotnet add package Umbraco.Forms --version 12.2.210.0.0Fixed in: 10.5.3dotnet add package Umbraco.Forms --version 10.5.38.0.0Fixed in: 8.13.13dotnet add package Umbraco.Forms --version 8.13.13References
- https://github.com/umbraco/Umbraco.Forms.Issues/security/advisories/GHSA-p572-p2rj-q5f4[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-35239[ADVISORY]
- https://docs.umbraco.com/umbraco-forms/developer/configuration#editing-configuration-values[WEB]
- https://docs.umbraco.com/umbraco-forms/release-notes#id-13.0.1-january-16th-2024[WEB]
- https://docs.umbraco.com/umbraco-forms/v/10.forms.latest/release-notes[WEB]
- https://docs.umbraco.com/umbraco-forms/v/10.forms.latest/release-notes#version-8[WEB]
- https://docs.umbraco.com/umbraco-forms/v/12.forms.latest/release-notes#id-12.2.2-january-16th-2024[WEB]
- https://github.com/umbraco/Umbraco.Forms.Issues[PACKAGE]