Silverstripe XSS in CMS Edit Page
Moderate severity
GitHub Reviewed
Published
May 23, 2024
to the GitHub Advisory Database
•
Updated May 23, 2024
Package
Affected versions
>= 3.1.18, < 3.1.19
>= 3.2.3, < 3.2.4
>= 3.3.1, < 3.3.2
Patched versions
3.1.19
3.2.4
3.3.2
Description
Published to the GitHub Advisory Database
May 23, 2024
Reviewed
May 23, 2024
Last updated
May 23, 2024
Due to a lack of parameter sanitisation a carefully crafted URL could be used to inject arbitrary HTML into the CMS Edit page.
An attacker could create a URL and share it with a site administrator to perform an attack.
References