CVE-2018-17256: XSS
Persistent cross-site scripting (XSS) vulnerability in Umbraco CMS 7.12.3 allows authenticated users to inject arbitrary web script via the Header Name of a content (Blog, Content Page, etc.). The vulnerability is exploited when updating or removing public access of a content.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17256?
CVE-2018-17256 is a persistent cross-site scripting (XSS) vulnerability in Umbraco CMS 7.12.3.
How does CVE-2018-17256 affect Umbraco CMS 7.12.3?
CVE-2018-17256 allows authenticated users to inject arbitrary web script via the Header Name of a content in Umbraco CMS 7.12.3.
How severe is CVE-2018-17256?
CVE-2018-17256 has a severity rating of medium (4.8).
How can the persistent XSS vulnerability in Umbraco CMS 7.12.3 be exploited?
The persistent XSS vulnerability in Umbraco CMS 7.12.3 is exploited when updating or removing public access of a content.
Is there a fix available for CVE-2018-17256?
Yes, users of Umbraco CMS 7.12.3 should update to a version that includes the fix for the vulnerability.