CVE-2017-15279: XSS
Cross-site scripting (XSS) vulnerability in Umbraco CMS before 7.7.3 allows remote attackers to inject arbitrary web script or HTML via the "page name" (aka nodename) parameter during the creation of a new page, related to Umbraco.Web.UI/umbraco/dialogs/Publish.aspx.cs and Umbraco.Web/umbraco.presentation/umbraco/dialogs/notifications.aspx.cs.
Other sources
Cross-site scripting (XSS) vulnerability in Umbraco CMS before 7.7.3 allows remote attackers to inject arbitrary web script or HTML via the "page name" (aka nodename) parameter during the creation of a new page, related to Umbraco.Web.UI/umbraco/dialogs/Publish.aspx.cs and Umbraco.Web/umbraco.presentation/umbraco/dialogs/notifications.aspx.cs.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15279?
CVE-2017-15279 has been rated as Medium severity due to its potential for exploiting cross-site scripting (XSS).
How do I fix CVE-2017-15279?
To fix CVE-2017-15279, upgrade Umbraco CMS to version 7.7.3 or later which resolves the vulnerability.
What versions are affected by CVE-2017-15279?
CVE-2017-15279 affects Umbraco CMS versions prior to 7.7.3, specifically up to and including 7.7.2.
What type of vulnerability is CVE-2017-15279?
CVE-2017-15279 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Where in Umbraco CMS is CVE-2017-15279 located?
CVE-2017-15279 is related to the "page name" parameter during the creation of a new page in Umbraco CMS.