{"id":"GHSA-572q-86rr-5vgq","summary":"Withdrawn Advisory: Umbraco Rich Text Display allows Cross-Site Scripting","details":"# Withdrawn Advisory\nThis advisory has been withdrawn because the issue is a [documented security](https://docs.umbraco.com/umbraco-cms/reference/security/serverside-sanitizing). This link is maintained to preserve external references. For more information, see https://github.com/github/advisory-database/pull/5270.\n\n# Original Advisory\nA stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.","aliases":["CVE-2024-55488"],"modified":"2026-09-10T03:50:56.774053982Z","published":"2025-01-22T18:31:55Z","withdrawn":"2025-02-13T16:44:44Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-02-07T20:39:55Z","nvd_published_at":"2025-01-22T16:15:29Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-55488"},{"type":"WEB","url":"https://github.com/github/advisory-database/pull/5270"},{"type":"WEB","url":"https://github.com/umbraco/Umbraco-CMS/pull/17164"},{"type":"PACKAGE","url":"https://github.com/umbraco/Umbraco-CMS"},{"type":"WEB","url":"https://github.com/umbraco/Umbraco-CMS/releases/tag/release-15.0.0-rc1"},{"type":"WEB","url":"https://www.nccgroup.com/us/research-blog/technical-advisory-cross-site-scripting-in-umbraco-rich-text-display"},{"type":"WEB","url":"http://umbraco.com"}],"affected":[{"package":{"name":"Umbraco.Cms.Infrastructure","ecosystem":"NuGet","purl":"pkg:nuget/Umbraco.Cms.Infrastructure"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.0.0"}]}],"versions":["10.0.0","10.0.0-rc5","10.0.1","10.1.0","10.1.0-rc","10.1.0-rc2","10.1.1","10.2.0","10.2.0-rc","10.2.1","10.3.0","10.3.0-rc","10.3.1","10.3.2","10.4.0","10.4.0-rc","10.4.1","10.4.2","10.5.0","10.5.0-rc","10.5.1","10.6.0","10.6.0-rc","10.6.1","10.7.0","10.7.0-rc","10.8.0","10.8.0-rc","10.8.1","10.8.10","10.8.11","10.8.2","10.8.3","10.8.4","10.8.5","10.8.6","10.8.7","10.8.8","10.8.9","11.0.0","11.0.0-rc4","11.0.0-rc5","11.0.0-rc6","11.1.0","11.1.0-rc","11.2.0","11.2.0-rc","11.2.1","11.2.2","11.3.0","11.3.0-rc","11.3.1","11.4.0","11.4.0-rc","11.4.1","11.4.2","11.5.0","11.5.0-rc","12.0.0","12.0.0-rc1","12.0.0-rc2","12.0.0-rc3","12.0.0-rc4","12.0.0-rc5","12.0.1","12.1.0","12.1.0-rc","12.1.1","12.1.2","12.2.0","12.2.0-rc","12.3.0","12.3.0-rc","12.3.1","12.3.10","12.3.2","12.3.3","12.3.4","12.3.5","12.3.6","12.3.7","12.3.8","12.3.9","13.0.0","13.0.0-rc2","13.0.0-rc3","13.0.0-rc4","13.0.0-rc5","13.0.1","13.0.2","13.0.3","13.1.0","13.1.0-rc","13.1.1","13.10.0","13.10.0-rc","13.10.1","13.11.0","13.11.0-rc","13.11.0-rc2","13.12.0","13.12.0-rc","13.12.0-rc2","13.12.1","13.13.0","13.13.0-rc","13.13.0-rc2","13.13.0-rc3","13.13.1","13.14.0","13.14.0-rc","13.14.0-rc2","13.14.0-rc3","13.15.0","13.15.0-rc","13.15.1","13.16.0","13.16.0-rc","13.16.1","13.2.0","13.2.0-rc","13.2.1","13.2.2","13.3.0","13.3.0-rc","13.3.1","13.3.2","13.4.0","13.4.0-rc","13.4.0-rc2","13.4.1","13.5.0","13.5.0-rc","13.5.1","13.5.2","13.5.3","13.6.0","13.6.0-rc","13.6.0-rc2","13.7.0","13.7.0-rc","13.7.1","13.7.2","13.8.0","13.8.0-rc","13.8.1","13.9.0","13.9.0-rc","13.9.1","13.9.2","13.9.3","14.0.0","14.0.0-rc1","14.0.0-rc2","14.0.0-rc3","14.0.0-rc4","14.0.0-rc5","14.1.0","14.1.0-rc","14.1.0-rc2","14.1.1","14.1.2","14.2.0","14.2.0-rc","14.2.0-rc2","14.2.0-rc3","14.3.0","14.3.0-rc","14.3.1","14.3.2","14.3.3","14.3.4","9.0.0","9.0.0-rc004","9.0.1","9.1.0","9.1.0-rc","9.1.1","9.1.2","9.2.0","9.2.0-rc","9.3.0","9.3.0-rc","9.3.1","9.4.0","9.4.0-rc","9.4.1","9.4.2","9.4.3","9.5.0","9.5.0-rc","9.5.0-rc2","9.5.0-rc3","9.5.1","9.5.2","9.5.3","9.5.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-572q-86rr-5vgq/GHSA-572q-86rr-5vgq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}