silverstripe/framework has Cross-site Scripting vulnerability in RedirectorPage
Moderate severity
GitHub Reviewed
Published
May 27, 2024
to the GitHub Advisory Database
Package
Affected versions
>= 3.4.0-rc1, < 3.4.6
>= 3.5.0-rc1, < 3.5.4
Patched versions
3.4.6
3.5.4
Description
Published to the GitHub Advisory Database
May 27, 2024
Reviewed
May 27, 2024
RedirectorPage will allow users to specify a non-url malicious script as the redirection path without validation. Users which follow this url may allow this script to execute within their browser.
References