First published: Tue Dec 12 2023(Updated: )
#### Impact Cross-site scripting (XSS) enable attackers to bring malicious content into a website or application. #### Explanation of the vulnerability A DOM-XSS can be exploited when users are successfully logging into the Backoffice.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Umbraco.CMS | >=11.0.0<12.3.4 | 12.3.4 |
nuget/Umbraco.CMS | >=10.0.0<10.8.1 | 10.8.1 |
Umbraco CMS | >=10.0.0<10.8.1 | |
Umbraco CMS | >=12.0.0<12.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48313 is rated as a critical vulnerability due to the potential for cross-site scripting (XSS) attacks.
To fix CVE-2023-48313, upgrade Umbraco.CMS to version 12.3.4 or 10.8.1.
CVE-2023-48313 affects Umbraco CMS versions between 11.0.0 and 12.3.4 and versions between 10.0.0 and 10.8.1.
Yes, CVE-2023-48313 can be exploited remotely by attackers through crafted payloads.
Exploitation of CVE-2023-48313 can lead to unauthorized access and the ability to execute malicious scripts in the context of the user’s browser.