CVE-2024-10761
Umbraco
CVE-2024-10761: Cross-site Scripting (XSS) Vulnerability in Umbraco CMS. A problematic vulnerability has been discovered in Umbraco CMS impacting the Dashboard component. Specifically, manipulating the 'culture' argument in the /Umbraco/preview/frame?id{}
file allows for cross-site scripting attacks. This XSS vulnerability enables remote attackers to inject malicious scripts into web pages viewed by other users. While the CVSS score is 4.3, the SOCRadar Vulnerability Risk Score (SVRS) is 53, indicating a moderate level of risk. An exploit is publicly available, increasing the likelihood of active exploitation. Upgrade to versions 10.8.8, 13.5.3, 14.3.2, or 15.1.2 to mitigate this security risk and protect your Umbraco CMS installation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.