Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
Moderate severity
GitHub Reviewed
Published
Jan 14, 2025
in
umbraco/Umbraco.Forms.Issues
•
Updated Jan 14, 2025
Description
Published by the National Vulnerability Database
Jan 14, 2025
Published to the GitHub Advisory Database
Jan 14, 2025
Reviewed
Jan 14, 2025
Last updated
Jan 14, 2025
Impact
Character limits configured by editors for short and long answer fields are validated only client-side, not server-side.
Patches
Patched in 8.13.16, 10.5.7, 13.2.2, 14.1.2
References