CVE-2023-38694

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
12/12/2023
Last modified:
18/12/2023

Description

Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.1.0, a user with access to a specific part of the backoffice is able to inject HTML code into a form where it is not intended. Versions 8.18.10, 10.7.0, and 12.1.0 contain a patch for this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:* 8.0.0 (including) 8.18.10 (excluding)
cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:* 9.0.0 (including) 10.7.0 (excluding)
cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:* 11.0.0 (including) 12.1.0 (excluding)