Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vvxf-r4vm-2vm6

Опубликовано: 21 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Reflected XSS in querystring parameters

An attacker could inject a XSS payload in a Silverstripe CMS response by carefully crafting a return URL on a /dev/build or /Security/login request.

To exploit this vulnerability, an attacker would need to convince a user to follow a link with a malicious payload.

This will only affect projects configured to output PHP warnings to the browser. By default, Silverstripe CMS will only output PHP warnings if your SS_ENVIRONMENT_TYPE environment variable is set to dev. Production sites should always set SS_ENVIRONMENT_TYPE to live.

Пакеты

Наименование

silverstripe/framework

composer
Затронутые версииВерсия исправления

>= 4.0.0, < 4.11.13

4.11.13

EPSS

Процентиль: 71%
0.0068
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 3 лет назад

Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.

EPSS

Процентиль: 71%
0.0068
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79