Skip to content

Umbraco Commerce vulnerable to Stored Cross-site Scripting on Print Functionality

Moderate severity GitHub Reviewed Published May 28, 2024 in umbraco/Umbraco.Commerce.Issues • Updated Jun 5, 2024

Package

nuget Umbraco.Commerce (NuGet)

Affected versions

>= 12.0.0, < 12.1.4
< 10.0.5

Patched versions

12.1.4
10.0.5

Description

Impact

Stored Cross-site scripting (XSS) enable attackers to inject malicious code into Print Functionality

Patches

12.1.4, 10.0.5

References

https://docs.umbraco.com/umbraco-commerce/release-notes#id-13.0.0-december-13th-2023

References

@netcamo netcamo published to umbraco/Umbraco.Commerce.Issues May 28, 2024
Published by the National Vulnerability Database May 28, 2024
Published to the GitHub Advisory Database May 28, 2024
Reviewed May 28, 2024
Last updated Jun 5, 2024

Severity

Moderate
5.4
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Weaknesses

CVE ID

CVE-2024-35240

GHSA ID

GHSA-rpj9-xjwm-wr6w

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.