Логотип exploitDog
bind:CVE-2024-53277
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-53277

Количество 2

Количество 2

nvd логотип

CVE-2024-53277

около 1 года назад

Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HTML markup. This is an intentional feature, allowing links and other relevant HTML markup for the given message. Some form messages include content that the user can provide. There are scenarios in the CMS where that content doesn't get correctly sanitised prior to being included in the form message, resulting in an XSS vulnerability. This issue has been addressed in silverstripe/framework version 5.3.8 and users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-ff6q-3c9c-6cf5

около 1 года назад

Silverstripe Framework has a XSS in form messages

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-53277

Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HTML markup. This is an intentional feature, allowing links and other relevant HTML markup for the given message. Some form messages include content that the user can provide. There are scenarios in the CMS where that content doesn't get correctly sanitised prior to being included in the form message, resulting in an XSS vulnerability. This issue has been addressed in silverstripe/framework version 5.3.8 and users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-ff6q-3c9c-6cf5

Silverstripe Framework has a XSS in form messages

CVSS3: 5.4
0%
Низкий
около 1 года назад

Уязвимостей на страницу