Umbraco
cpe:2.3:a:umbraco:umbraco:*:*:*:*:*:*:*
- >= 14.0.0, < 14.3.2
- ~15.1
A cross-site scripting vulnerability has been identified in Umbraco, a .NET content management system, affecting versions 14.0.0 prior to 14.3.2 and 15.1.2. This vulnerability allows authenticated users to inject malicious scripts when viewing certain localized backoffice components. The issue arises because user input is not properly sanitized before being displayed, particularly in the dictionary workspace.
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
To reproduce this vulnerability, an authenticated user can navigate to specific localized backoffice components within the Umbraco dictionary workspace. The injected script, such as a JavaScript alert, will be executed, demonstrating the cross-site scripting vulnerability.
Users can upgrade to Umbraco versions 14.3.2 or 15.1.2, both of which include the necessary patch to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.