CVE-2024-35239: Stored Cross-site Scripting on Components of Umbraco Forms
Impact Authenticated user that has access to edit Forms may inject unsafe code into Forms components.
Patches Issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).
References https://docs.umbraco.com/umbraco-forms/release-notes#id-13.0.1-january-16th-2024 https://docs.umbraco.com/umbraco-forms/v/12.forms.latest/release-notes#id-12.2.2-january-16th-2024 https://docs.umbraco.com/umbraco-forms/v/10.forms.latest/release-notes https://docs.umbraco.com/umbraco-forms/developer/configuration#editing-configuration-values
Other sources
Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe code into Forms components. This issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to one of the patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35239?
CVE-2024-35239 is a moderate severity vulnerability allowing authenticated users to inject unsafe code into Forms components.
How do I fix CVE-2024-35239?
To mitigate CVE-2024-35239, configure TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to patched versions 13.0.1, 12.2.2, 10.5.3, or 8.13.13.
Who is affected by CVE-2024-35239?
CVE-2024-35239 affects users with access to edit Forms in affected versions of Umbraco.Forms.
What are the patched versions for CVE-2024-35239?
The patched versions for CVE-2024-35239 are 13.0.1, 12.2.2, 10.5.3, and 8.13.13.
What can happen if CVE-2024-35239 is exploited?
If exploited, CVE-2024-35239 allows attackers to inject malicious code that could compromise the integrity of Forms components.