Описание
Silverstripe XSS in dev/build returnURL Parameter
A XSS risk exists in the returnURL parameter passed to dev/build. An unvalidated url could cause the user to redirect to an unverified third party url outside of the site.
This issue is resolved in framework 3.1.14 stable release.
Пакеты
Наименование
silverstripe/framework
composer
Затронутые версииВерсия исправления
< 3.1.14
3.1.14
4.7 Medium
CVSS3
Дефекты
CWE-79
4.7 Medium
CVSS3
Дефекты
CWE-79