CVE-2024-35240

MEDIUM

Umbraco.Commerce 12.0.0-12.1.3 and < 10.0.5 - Stored Cross-Site Scripting in Print Functionality

Title source: llm
STIX 2.1

Description

Umbraco Commerce is an open source dotnet ecommerce solution. In affected versions there exists a stored Cross-site scripting (XSS) issue which would enable attackers to inject malicious code into Print Functionality. This issue has been addressed in versions 12.1.4, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Scores

CVSS v3 5.4
EPSS 0.0027
EPSS Percentile 50.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (3)
nuget/Umbraco.Commerce 12.0.0 - 12.1.4NuGet
umbraco/Umbraco.Commerce.Issues < 10.0.5
umbraco/Umbraco.Commerce.Issues >= 12.0.0, < 12.1.4
Published May 28, 2024
Tracked Since Feb 18, 2026