Umbraco.Forms
cpe:2.3:a:umbraco:umbraco_forms:*:*:*:*:*:*:*
- <= 10.5.7
- < 8.13.16
A vulnerability exists in Umbraco.Forms versions through 10.5.7 and prior to 8.13.16, allowing character limits set by editors for short and long answer fields to be validated only on the client side, with no server-side enforcement. This could lead to fields being submitted with excessive characters, potentially causing issues downstream. The vulnerability arises because the framework does not properly validate input lengths on the server, leaving room for overlong submissions that could disrupt application functionality.
Exploitation of this vulnerability could result in improper input validation, allowing users to submit responses that exceed the intended character limits. This could lead to data integrity issues or application errors, particularly if the overlong input is not handled correctly by the system.
Users are advised to upgrade to Umbraco.Forms versions 8.13.16, 10.5.7, 13.2.2, or 14.1.2.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.