MEDIUM4.6
GHSA-wv8v-rmw2-25wc
XSS/HTML Injection Vulnerability in Umbraco Backoffice Components
Quick fix
GHSA-wv8v-rmw2-25wc — Umbraco.Cms.StaticAssets: upgrade to the fixed version with the command below.
dotnet add package Umbraco.Cms.StaticAssets --version 14.3.2Details
### Impact Authenticated users are able to exploit an XSS vulnerability when viewing certain localized backoffice components.
### Patches Will be patched in 14.3.2 and 15.1.2.
Note: This issue was reported by Pratik Patil from NetSPI @Nexusss-ppatil
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/Umbraco.Cms.StaticAssets
Introduced in:
14.0.0Fixed in: 14.3.2Fix
dotnet add package Umbraco.Cms.StaticAssets --version 14.3.2NuGet/Umbraco.Cms.StaticAssets
Introduced in:
15.0.0Fixed in: 15.1.2Fix
dotnet add package Umbraco.Cms.StaticAssets --version 15.1.2npm/@umbraco-cms/backoffice
Introduced in:
14.0.0Fixed in: 14.3.2Fix
npm install @umbraco-cms/backoffice@14.3.2npm/@umbraco-cms/backoffice
Introduced in:
15.0.0Fixed in: 15.1.2Fix
npm install @umbraco-cms/backoffice@15.1.2