Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1wNTcyLXAycmotcTVmNM4AA8jE

Umbraco Forms components vulnerable to Stored Cross-site Scripting

Impact

Authenticated user that has access to edit Forms may inject unsafe code into Forms components.

Patches

Issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).

References

https://docs.umbraco.com/umbraco-forms/release-notes#id-13.0.1-january-16th-2024
https://docs.umbraco.com/umbraco-forms/v/12.forms.latest/release-notes#id-12.2.2-january-16th-2024
https://docs.umbraco.com/umbraco-forms/v/10.forms.latest/release-notes
https://docs.umbraco.com/umbraco-forms/developer/configuration#editing-configuration-values

Permalink: https://github.com/advisories/GHSA-p572-p2rj-q5f4
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wNTcyLXAycmotcTVmNM4AA8jE
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: 4 months ago
Updated: 4 months ago


CVSS Score: 2.7
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Identifiers: GHSA-p572-p2rj-q5f4, CVE-2024-35239
References: Repository: https://github.com/umbraco/Umbraco.Forms.Issues
Blast Radius: 1.0

Affected Packages

nuget:Umbraco.Forms
Dependent packages: 9
Dependent repositories: 0
Downloads: 989,238 total
Affected Version Ranges: >= 8.0.0, < 8.13.13, >= 10.0.0, < 10.5.3, >= 12.0.0, < 12.2.2, >= 13.0.0, < 13.0.1
Fixed in: 8.13.13, 10.5.3, 12.2.2, 13.0.1
All affected versions: 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, 10.0.5, 10.1.0, 10.1.1, 10.1.2, 10.1.3, 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.3.0, 10.3.1, 10.3.2, 10.3.3, 10.4.0, 10.5.0, 10.5.1, 10.5.2, 12.0.0, 12.1.0, 12.1.1, 12.1.2, 12.2.0, 12.2.1, 13.0.0
All unaffected versions: 4.0.0, 9.0.0, 9.0.1, 9.1.0, 9.1.1, 9.2.0, 9.2.1, 9.2.2, 9.3.0, 9.4.0, 9.4.1, 9.4.2, 9.5.0, 9.5.1, 9.5.2, 9.5.3, 9.5.4, 9.5.5, 9.5.6, 9.5.7, 9.5.8, 9.5.9, 10.5.3, 10.5.4, 10.5.5, 10.5.6, 10.5.7, 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.1.0, 11.1.1, 11.1.2, 11.1.3, 11.2.0, 11.2.1, 12.2.2, 12.2.3, 12.2.4, 13.0.1, 13.0.2, 13.1.0, 13.1.1, 13.1.2, 13.2.0, 13.2.1, 13.2.2, 13.2.3, 14.0.0, 14.0.1, 14.0.2, 14.1.0, 14.1.1, 14.1.2, 14.1.3