CVE-2020-5809: XSS
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5809?
CVE-2020-5809 is a stored XSS vulnerability that exists in Umbraco CMS versions <= 8.9.1 or current.
How does the vulnerability in Umbraco CMS CVE-2020-5809 work?
An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor in Umbraco CMS, as TinyMCE is configured to allow iframes by default.
Is Umbraco CMS version 8.9.1 affected by CVE-2020-5809?
Yes, Umbraco CMS version 8.9.1 is affected by CVE-2020-5809.
How severe is the vulnerability in Umbraco CMS CVE-2020-5809?
The severity of the vulnerability in Umbraco CMS CVE-2020-5809 is medium, with a severity score of 5.4.
How can I fix the vulnerability in Umbraco CMS CVE-2020-5809?
To fix the vulnerability in Umbraco CMS CVE-2020-5809, it is recommended to update to a version higher than 8.9.1 or apply the necessary security patches.