The provided vulnerability description and references indicate a stored XSS vulnerability in Umbraco CMS 7.12.3 via the 'Header Name' field during public access updates. However, no specific code snippets, commit diffs, or implementation details are provided in the advisory to identify exact vulnerable functions. The lack of GitHub patch information and commit diffs makes it impossible to confidently pinpoint the affected functions. While the vulnerability likely exists in functions handling input sanitization for the Header Name field during content updates or public access management, insufficient technical details prevent high-confidence identification of specific functions/paths.