XSS/HTML Injection Vulnerability in Umbraco Preview Badge
Moderate severity
GitHub Reviewed
Published
Jan 21, 2025
in
umbraco/Umbraco-CMS
•
Updated Jan 21, 2025
Package
Affected versions
>= 10.8.7, < 10.8.8
>= 11.0.0, < 13.5.3
>= 14.0.0, < 14.3.2
>= 15.0.0, < 15.1.2
Patched versions
10.8.8
13.5.3
14.3.2
15.1.2
Description
Published to the GitHub Advisory Database
Jan 21, 2025
Reviewed
Jan 21, 2025
Last updated
Jan 21, 2025
Impact
Authenticated users are able to exploit an XSS vulnerability when viewing previewed content.
Patches
Will be patched in 10.8.8, 13.5.3, 14.3.2 and 15.1.2.
Workarounds
None available.
References