CVE-2023-49279

Umbraco is an ASP.NET content management system (CMS). Starting in version 7.0.0 and prior to versions 7.15.11, 8.18.9, 10.7.0, 11.5.0, and 12.2.0, a user with access to the backoffice can upload SVG files that include scripts. If the user can trick another user to load the media directly in a browser, the scripts can be executed. Versions 7.15.11, 8.18.9, 10.7.0, 11.5.0, and 12.2.0 contain a patch for this issue. Some workarounds are available. Implement the server side file validation or serve all media from an different host (e.g cdn) than where Umbraco is hosted.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:33

Type Values Removed Values Added
References () https://docs.umbraco.com/umbraco-cms/reference/security/serverside-file-validation - Product () https://docs.umbraco.com/umbraco-cms/reference/security/serverside-file-validation - Product
References () https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-6xmx-85x3-4cv2 - Vendor Advisory () https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-6xmx-85x3-4cv2 - Vendor Advisory
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 3.7

15 Dec 2023, 18:36

Type Values Removed Values Added
References () https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-6xmx-85x3-4cv2 - () https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-6xmx-85x3-4cv2 - Vendor Advisory
References () https://docs.umbraco.com/umbraco-cms/reference/security/serverside-file-validation - () https://docs.umbraco.com/umbraco-cms/reference/security/serverside-file-validation - Product
CPE cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

12 Dec 2023, 20:20

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-12 20:15

Updated : 2024-11-21 08:33


NVD link : CVE-2023-49279

Mitre link : CVE-2023-49279

CVE.ORG link : CVE-2023-49279


JSON object : View

Products Affected

umbraco

  • umbraco_cms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')