CVE-2024-35218: Umbraco CMS Vulnerable to Stored XSS on Content Page Through Markdown Editor Preview Pane
Impact Stored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application.
Affected versions Umbraco CMS >= 8.00
Patches This is fixed in 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer
Other sources
Umbraco CMS is an ASP.NET CMS used by more than 730.000 websites. Stored Cross-site scripting (XSS) enable attackers that have access to backoffice to bring malicious content into a website or application. This vulnerability has been patched in version(s) 8.18.13, 10.8.4, 12.3.7, 13.1.1 by implementing IHtmlSanitizer.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35218?
CVE-2024-35218 has a medium severity rating due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-35218?
To fix CVE-2024-35218, update Umbraco CMS to version 8.18.13, 10.8.4, 12.3.7, or 13.1.1.
Which versions of Umbraco CMS are affected by CVE-2024-35218?
CVE-2024-35218 affects all versions of Umbraco CMS greater than or equal to 8.00.
What type of vulnerability is identified in CVE-2024-35218?
CVE-2024-35218 is a stored cross-site scripting (XSS) vulnerability.
What impact does CVE-2024-35218 have on users?
The impact of CVE-2024-35218 allows attackers with access to the back office to bring in malicious content, compromising the website or application.