XSS/HTML Injection Vulnerability in Umbraco Backoffice Components
Description
Published by the National Vulnerability Database
Jan 21, 2025
Published to the GitHub Advisory Database
Jan 21, 2025
Reviewed
Jan 21, 2025
Impact
Authenticated users are able to exploit an XSS vulnerability when viewing certain localized backoffice components.
Patches
Will be patched in 14.3.2 and 15.1.2.
Note:
This issue was reported by Pratik Patil from NetSPI @Nexusss-ppatil
References