PT-2024-32830 · Umbraco · Umbraco

·

CVE-2024-47819

·

Published

2024-10-22

·

Updated

2024-10-25

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Umbraco versions 14.0.0 through 14.3.0 Umbraco versions prior to 15.0.0
Description The issue allows for cross-site scripting, which can be leveraged to gain access to higher-privilege endpoints. If a user with admin privileges runs the code, it can potentially elevate all users and grant them admin privileges or access protected content.
Recommendations For Umbraco versions 14.0.0 through 14.3.0, update to version 14.3.1 to resolve the issue. For Umbraco versions prior to 15.0.0, update to version 15.0.0 to resolve the issue. As a temporary workaround, ensure that access to the Dictionary section is only granted to trusted users.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-47819
GHSA-C5G6-6XF7-QXP3

Affected Products

Umbraco