MEDIUM 5.4 NuGet
Umbraco CMS vulnerable to stored XSS
GHSA-95qr-67rx-9pgh · CVE-2020-5809
Published · Modified
Description
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS.
Ready to move
Start Securing
Free, no credit card | First findings in minutes