{"id":"GHSA-c5g6-6xf7-qxp3","summary":"Umbraco CMS vulnerable to stored Cross-site Scripting in the \"dictionary name\" on Dictionary section","details":"### Impact\nThis can be leveraged to gain access to higher-privilege endpoints, e.g. if you get a user with admin privileges to run the code, you can potentially elevate all users and grant them admin privileges or access protected content.\n\n### Patches\nWill be patched in 14.3.1 and 15.0.0.\n\n### Workarounds\nEnsure that access to the Dictionary section is only granted to trusted users.\n\n","aliases":["CVE-2024-47819"],"modified":"2024-10-22T19:32:47.036714Z","published":"2024-10-22T17:50:08Z","database_specific":{"nvd_published_at":"2024-10-22T16:15:07Z","cwe_ids":["CWE-79","CWE-80"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-10-22T17:50:08Z"},"references":[{"type":"WEB","url":"https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-c5g6-6xf7-qxp3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47819"},{"type":"PACKAGE","url":"https://github.com/umbraco/Umbraco-CMS"}],"affected":[{"package":{"name":"Umbraco.Cms.StaticAssets","ecosystem":"NuGet","purl":"pkg:nuget/Umbraco.Cms.StaticAssets"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14.0.0"},{"fixed":"14.3.1"}]}],"versions":["14.0.0","14.1.0","14.1.0-rc","14.1.0-rc2","14.1.1","14.1.2","14.2.0","14.2.0-rc","14.2.0-rc2","14.2.0-rc3","14.3.0","14.3.0-rc"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-c5g6-6xf7-qxp3/GHSA-c5g6-6xf7-qxp3.json"}},{"package":{"name":"@umbraco-cms/backoffice","ecosystem":"npm","purl":"pkg:npm/%40umbraco-cms/backoffice"},"ranges":[{"type":"SEMVER","events":[{"introduced":"14.0.0"},{"fixed":"14.3.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-c5g6-6xf7-qxp3/GHSA-c5g6-6xf7-qxp3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N"}]}