VDB
Sign up
MEDIUM4.6

GHSA-wv8v-rmw2-25wc

XSS/HTML Injection Vulnerability in Umbraco Backoffice Components

Quick fix

GHSA-wv8v-rmw2-25wc — Umbraco.Cms.StaticAssets: upgrade to the fixed version with the command below.

dotnet add package Umbraco.Cms.StaticAssets --version 14.3.2

Details

### Impact Authenticated users are able to exploit an XSS vulnerability when viewing certain localized backoffice components.

### Patches Will be patched in 14.3.2 and 15.1.2.

Note: This issue was reported by Pratik Patil from NetSPI @Nexusss-ppatil

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/Umbraco.Cms.StaticAssets
Introduced in: 14.0.0Fixed in: 14.3.2
Fixdotnet add package Umbraco.Cms.StaticAssets --version 14.3.2
NuGet/Umbraco.Cms.StaticAssets
Introduced in: 15.0.0Fixed in: 15.1.2
Fixdotnet add package Umbraco.Cms.StaticAssets --version 15.1.2
npm/@umbraco-cms/backoffice
Introduced in: 14.0.0Fixed in: 14.3.2
Fixnpm install @umbraco-cms/backoffice@14.3.2
npm/@umbraco-cms/backoffice
Introduced in: 15.0.0Fixed in: 15.1.2
Fixnpm install @umbraco-cms/backoffice@15.1.2

References