First published: Thu Oct 12 2017(Updated: )
Cross-site scripting (XSS) vulnerability in Umbraco CMS before 7.7.3 allows remote attackers to inject arbitrary web script or HTML via the "page name" (aka nodename) parameter during the creation of a new page, related to `Umbraco.Web.UI/umbraco/dialogs/Publish.aspx.cs` and `Umbraco.Web/umbraco.presentation/umbraco/dialogs/notifications.aspx.cs`.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/UmbracoCMS.Web | <7.7.3 | 7.7.3 |
Umbraco CMS | <=7.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15279 has been rated as Medium severity due to its potential for exploiting cross-site scripting (XSS).
To fix CVE-2017-15279, upgrade Umbraco CMS to version 7.7.3 or later which resolves the vulnerability.
CVE-2017-15279 affects Umbraco CMS versions prior to 7.7.3, specifically up to and including 7.7.2.
CVE-2017-15279 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
CVE-2017-15279 is related to the "page name" parameter during the creation of a new page in Umbraco CMS.