VDB
Sign up
MEDIUM4.3

GHSA-v98m-398x-269r

DOM-XSS on Backoffice login screen.

Quick fix

GHSA-v98m-398x-269r — Umbraco.CMS: upgrade to the fixed version with the command below.

dotnet add package Umbraco.CMS --version 10.8.1

Details

#### Impact Cross-site scripting (XSS) enable attackers to bring malicious content into a website or application.

#### Explanation of the vulnerability

A DOM-XSS can be exploited when users are successfully logging into the Backoffice.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/Umbraco.CMS
Introduced in: 10.0.0Fixed in: 10.8.1
Fixdotnet add package Umbraco.CMS --version 10.8.1
NuGet/Umbraco.CMS
Introduced in: 11.0.0Fixed in: 12.3.4
Fixdotnet add package Umbraco.CMS --version 12.3.4

References