Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mpqj-f4v3-334h

Опубликовано: 23 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Silverstripe Cross-site scripting vulnerability in VersionedRequestFilter

A cross-site scripting vulnerability in VersionedRequestFilter has been found.

If an incoming user request should not be able to access the requested stage, an error message is created for display on the CMS login page that they are redirected to. In this error message, the URL of the requested page is interpolated into the error message without being escaped; hence, arbitrary HTML can be injected into the CMS login page.

Пакеты

Наименование

silverstripe/framework

composer
Затронутые версииВерсия исправления

>= 3.3.2, < 3.3.3

3.3.3

Наименование

silverstripe/framework

composer
Затронутые версииВерсия исправления

>= 3.4.0, < 3.4.1

3.4.1

6.1 Medium

CVSS3

Дефекты

CWE-79

6.1 Medium

CVSS3

Дефекты

CWE-79