Описание
Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code.
Ссылки
- Broken LinkRelease NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Not ApplicableVendor Advisory
- Broken LinkRelease NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Not ApplicableVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.10.0 (включая)
cpe:2.3:a:silverstripe:framework:*:*:*:*:*:*:*:*
EPSS
Процентиль: 56%
0.00338
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
github
больше 3 лет назад
Stored XSS via HTML fields in SilverStripe Framework
EPSS
Процентиль: 56%
0.00338
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79