Executive brief
Umbraco CMS is a popular content management system used to build and manage websites. A stored cross-site scripting (XSS) vulnerability in the Dictionary section allows authenticated users with admin access to inject malicious code that executes when other users interact with the dictionary name field. An attacker with admin privileges could exploit this to elevate other users to admin status, grant unauthorized access, or manipulate site content.
Technical details
This is a stored cross-site scripting (CWE-79/CWE-80) vulnerability in the Umbraco CMS Dictionary section where user-supplied input in the "dictionary name" field is not properly neutralized before being stored and rendered in the web interface. The vulnerability requires network access, high-level privileges (admin role), and user interaction (victim must view the malicious dictionary name). An attacker with admin privileges can inject JavaScript that executes in the context of other admin users, potentially allowing privilege escalation, creation of additional admin accounts, or access to protected content. Patches are available in Umbraco CMS versions 14.3.1 and 15.0.0.
Affected products
- Umbraco CMS 14.0.0 through 14.3.0
Timeline
- 2024-10-22: disclosed
- 2024-10-22: patched: Patches released in versions 14.3.1 and 15.0.0