Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qp29-wcc2-vmpc

Опубликовано: 23 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Silverstripe HtmlEditor embed url sanitisation

"Add from URL" doesn't clearly sanitise URL server side

HtmlEditorField_Toolbar has an action HtmlEditorField_Toolbar#viewfile, which gets called by the CMS when adding a media "from a URL" (i.e. via oembed).

This action gets the URL to add in the GET parameter FileURL. However it doesn't do any URL sanitising server side. The current logic will pass this through to Oembed, which will probably reject most dangerous URLs, but it's possible future changes would break this.

Пакеты

Наименование

silverstripe/framework

composer
Затронутые версииВерсия исправления

>= 3.0.0, < 3.2.1

3.2.1

4.3 Medium

CVSS3

4.3 Medium

CVSS3