DOM-XSS on Backoffice login screen.
Moderate severity
GitHub Reviewed
Published
Dec 12, 2023
in
umbraco/Umbraco-CMS
•
Updated Apr 22, 2024
Package
Affected versions
>= 10.0.0, < 10.8.1
>= 11.0.0, < 12.3.4
Patched versions
10.8.1
12.3.4
Description
Published by the National Vulnerability Database
Dec 12, 2023
Published to the GitHub Advisory Database
Dec 13, 2023
Reviewed
Dec 13, 2023
Last updated
Apr 22, 2024
Impact
Cross-site scripting (XSS) enable attackers to bring malicious content into a website or application.
Explanation of the vulnerability
A DOM-XSS can be exploited when users are successfully logging into the Backoffice.
References