XSS/HTML Injection Vulnerability in Umbraco Preview Badge
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Jan 21, 2025 
          in
          
            umbraco/Umbraco-CMS
          
          •
          Updated Feb 19, 2025 
      
  
Package
Affected versions
>= 10.8.7, < 10.8.8
      >= 11.0.0, < 13.5.3
      >= 14.0.0, < 14.3.2
      >= 15.0.0, < 15.1.2
  Patched versions
10.8.8
      13.5.3
      14.3.2
      15.1.2
  >= 11.0.0, < 13.5.3
      >= 14.0.0, < 14.3.2
      >= 15.0.0, < 15.1.2
      >= 10.8.7, < 10.8.8
  13.5.3
      14.3.2
      15.1.2
      10.8.8
  Description
        Published to the GitHub Advisory Database
      Jan 21, 2025 
    
  
        Reviewed
      Jan 21, 2025 
    
  
        Last updated
      Feb 19, 2025 
    
  
Impact
Authenticated users are able to exploit an XSS vulnerability when viewing previewed content.
Patches
Will be patched in 10.8.8, 13.5.3, 14.3.2 and 15.1.2.
Workarounds
None available.
References