Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r32j-mr8p-hfp8

Опубликовано: 23 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Silverstripe XSS in TreeDropdownField and TreeMultiSelectField

A cross-site scripting vulnerability has been discovered in the TreeDropdownField and TreeMultiSelectField.

This vulnerability can only be exploited if a user with CMS access has posted malicious or unescaped HTML into any of the dataobjects used as a data source for either of these fields.

This has been resolved by ensuring that all dataobjects used as a data source have their content safely encoded.

Пакеты

Наименование

silverstripe/framework

composer
Затронутые версииВерсия исправления

>= 3.1.0, <= 3.1.9

3.1.10

6.1 Medium

CVSS3

Дефекты

CWE-79

6.1 Medium

CVSS3

Дефекты

CWE-79