MEDIUM4.3
GHSA-v98m-398x-269r
DOM-XSS on Backoffice login screen.
Quick fix
GHSA-v98m-398x-269r — Umbraco.CMS: upgrade to the fixed version with the command below.
dotnet add package Umbraco.CMS --version 10.8.1Details
#### Impact Cross-site scripting (XSS) enable attackers to bring malicious content into a website or application.
#### Explanation of the vulnerability
A DOM-XSS can be exploited when users are successfully logging into the Backoffice.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/Umbraco.CMS
Introduced in:
10.0.0Fixed in: 10.8.1Fix
dotnet add package Umbraco.CMS --version 10.8.1NuGet/Umbraco.CMS
Introduced in:
11.0.0Fixed in: 12.3.4Fix
dotnet add package Umbraco.CMS --version 12.3.4