Skip to content

Stored XSS on Components of Umbraco Forms

Low
netcamo published GHSA-p572-p2rj-q5f4 May 28, 2024

Package

nuget Umbraco.Forms (NuGet)

Affected versions

<13.0.1, <12.2.2, <10.5.3, <8.13.13

Patched versions

13.0.1, 12.2.2, 10.5.3, 8.13.13

Description

Impact

Authenticated user that has access to edit Forms may inject unsafe code into Forms components.

Patches

Issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).

References

https://docs.umbraco.com/umbraco-forms/release-notes#id-13.0.1-january-16th-2024
https://docs.umbraco.com/umbraco-forms/v/12.forms.latest/release-notes#id-12.2.2-january-16th-2024
https://docs.umbraco.com/umbraco-forms/v/10.forms.latest/release-notes
https://docs.umbraco.com/umbraco-forms/developer/configuration#editing-configuration-values

Severity

Low
2.7
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

CVE ID

CVE-2024-35239

Weaknesses

No CWEs

Credits