Количество 2
Количество 2
CVE-2022-25238
Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code.
GHSA-jx34-gqqq-r6gm
Stored XSS via HTML fields in SilverStripe Framework
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-25238 Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-jx34-gqqq-r6gm Stored XSS via HTML fields in SilverStripe Framework | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу