Description

Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe code into Forms components. This issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to one of the patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).

INFO

Published Date :

2024-05-28T20:15:28.512Z

Last Modified :

2024-08-02T03:07:46.872Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2024-35239 vulnerability.

Vendors Products
Umbraco
  • Umbraco Forms

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact