Vulnerability Description
Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe code into Forms components. This issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to one of the patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Umbraco | Umbraco Forms | < 8.13.13 |
Related Weaknesses (CWE)
References
- https://docs.umbraco.com/umbraco-forms/developer/configuration#editing-configuraProduct
- https://docs.umbraco.com/umbraco-forms/release-notes#id-13.0.1-january-16th-2024Release Notes
- https://docs.umbraco.com/umbraco-forms/v/10.forms.latest/release-notesRelease Notes
- https://docs.umbraco.com/umbraco-forms/v/12.forms.latest/release-notes#id-12.2.2Release Notes
- https://github.com/umbraco/Umbraco.Forms.Issues/security/advisories/GHSA-p572-p2Vendor Advisory
- https://docs.umbraco.com/umbraco-forms/developer/configuration#editing-configuraProduct
- https://docs.umbraco.com/umbraco-forms/release-notes#id-13.0.1-january-16th-2024Release Notes
- https://docs.umbraco.com/umbraco-forms/v/10.forms.latest/release-notesRelease Notes
- https://docs.umbraco.com/umbraco-forms/v/12.forms.latest/release-notes#id-12.2.2Release Notes
- https://github.com/umbraco/Umbraco.Forms.Issues/security/advisories/GHSA-p572-p2Vendor Advisory
FAQ
What is CVE-2024-35239?
CVE-2024-35239 is a vulnerability with a CVSS score of 2.7 (LOW). Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe code into Forms components. This issue can be m...
How severe is CVE-2024-35239?
CVE-2024-35239 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-35239?
Check the references section above for vendor advisories and patch information. Affected products include: Umbraco Umbraco Forms.