GHSA-xj94-rgf9-cq37
Dashboard / Vulnerabilities / GHSA-xj94-rgf9-cq37
Summary: Umbraco CMS vulnerable to stored XSS
Details: Cross-site scripting (XSS) vulnerability in Umbraco CMS before 7.7.3 allows remote attackers to inject arbitrary web script or HTML via the "page name" (aka nodename) parameter during the creation of a new page, related to `Umbraco.Web.UI/umbraco/dialogs/Publish.aspx.cs` and `Umbraco.Web/umbraco.presentation/umbraco/dialogs/notifications.aspx.cs`.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-15279, https://github.com/umbraco/Umbraco-CMS/commit/fe2b86b681455ac975b294652064b2718d4e2ba2, https://github.com/umbraco/Umbraco-CMS, http://issues.umbraco.org/issue/U4-10497
Affected packages
Package
Name: UmbracoCMS.Web
Purl: pkg:nuget/UmbracoCMS.Web
Affected ranges
Type: ECOSYSTEM
Events:
