Описание
Silverstripe has Cross-site Scripting (XSS) vulnerabilities inherited from TinyMCE
TinyMCE 4.x is vulnerable to several XSS vectors, which had been patched in later versions. Two of these have been identified as affecting silverstripe/admin.
Only Silverstripe CMS 4 is affected by this issue. It's not possible to upgrade Silverstripe CMS 4 to use a more recent release of TinyMCE without introducing breaking changes. Instead, the security patches that shipped in later releases of TinyMCE have been backported to the TinyMCE version bundled in silverstripe/admin.
Silverstripe CMS 5 is not affected by those vulnerabilities because it uses TinyMCE 6.
You can find more information about the underlying vulnerabilities in those GitHub security advisories:
Пакеты
silverstripe/admin
< 1.13.6
1.13.6
5.4 Medium
CVSS3
5.4 Medium
CVSS3