First published: Tue Jan 21 2025(Updated: )
### Impact Authenticated users are able to exploit an XSS vulnerability when viewing certain localized backoffice components. ### Patches Will be patched in 14.3.2 and 15.1.2. Note: This issue was reported by Pratik Patil from NetSPI @Nexusss-ppatil
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
npm/@umbraco-cms/backoffice | >=15.0.0<15.1.2 | 15.1.2 |
npm/@umbraco-cms/backoffice | >=14.0.0<14.3.2 | 14.3.2 |
nuget/Umbraco.Cms.StaticAssets | >=15.0.0<15.1.2 | 15.1.2 |
nuget/Umbraco.Cms.StaticAssets | >=14.0.0<14.3.2 | 14.3.2 |
Umbraco CMS | >=14.0.0<14.3.2>=14.0.0<15.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24012 is classified as a medium severity XSS vulnerability affecting localized backoffice components.
To fix CVE-2025-24012, upgrade to versions 14.3.2 or 15.1.2 of the affected Umbraco packages.
CVE-2025-24012 affects the @umbraco-cms/backoffice and Umbraco.Cms.StaticAssets packages in specific version ranges.
CVE-2025-24012 was reported by Pratik Patil from NetSPI.
Patches for CVE-2025-24012 will be available in the upcoming releases of version 14.3.2 and 15.1.2.