First published: Wed Dec 30 2020(Updated: )
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS.
Credit: vulnreport@tenable.com vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/UmbracoCms.Core | <=8.9.1 | |
Umbraco CMS | <=8.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5809 is a stored XSS vulnerability that exists in Umbraco CMS versions <= 8.9.1 or current.
An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor in Umbraco CMS, as TinyMCE is configured to allow iframes by default.
Yes, Umbraco CMS version 8.9.1 is affected by CVE-2020-5809.
The severity of the vulnerability in Umbraco CMS CVE-2020-5809 is medium, with a severity score of 5.4.
To fix the vulnerability in Umbraco CMS CVE-2020-5809, it is recommended to update to a version higher than 8.9.1 or apply the necessary security patches.