CVE-2024-55488: XSS
Withdrawn Advisory This advisory has been withdrawn because the issue is a documented security. This link is maintained to preserve external references. For more information, see https://github.com/github/advisory-database/pull/5270.
Original Advisory A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Other sources
A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: This has been disputed by the vendor since this potential attack is only possible via authenticated users who have been manually allowed access to the CMS. There was a deliberate decision made not to apply HTML sanitization at the product level.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Umbraco.Cms.Infrastructureto a version that resolves this vulnerability.Fixed in 15.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55488?
CVE-2024-55488 is rated as a high severity vulnerability due to its potential for allowing arbitrary script execution.
How do I fix CVE-2024-55488?
To fix CVE-2024-55488, upgrade Umbraco CMS to version 14.3.2 or later as the patched version addresses this vulnerability.
Who is affected by CVE-2024-55488?
CVE-2024-55488 affects Umbraco CMS v14.3.1 installations, enabling stored cross-site scripting attacks.
What type of vulnerability is CVE-2024-55488?
CVE-2024-55488 is classified as a stored cross-site scripting (XSS) vulnerability.
What are the potential impacts of CVE-2024-55488?
Exploitation of CVE-2024-55488 could allow attackers to execute arbitrary web scripts or HTML, compromising user data and site integrity.