CVE-2024-35239

medium

Description

Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe code into Forms components. This issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to one of the patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).

References

https://github.com/umbraco/Umbraco.Forms.Issues/security/advisories/GHSA-p572-p2rj-q5f4

https://docs.umbraco.com/umbraco-forms/v/12.forms.latest/release-notes#id-12.2.2-january-16th-2024

https://docs.umbraco.com/umbraco-forms/v/10.forms.latest/release-notes

https://docs.umbraco.com/umbraco-forms/release-notes#id-13.0.1-january-16th-2024

https://docs.umbraco.com/umbraco-forms/developer/configuration#editing-configuration-values

Details

Source: Mitre, NVD

Published: 2024-05-28

Updated: 2026-01-05

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.4

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00463