Логотип exploitDog
bind:CVE-2025-30148
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-30148

Количество 2

Количество 2

nvd логотип

CVE-2025-30148

10 месяцев назад

Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to edit content in the CMS could send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The payload would be sanitized on the client-side, but server-side sanitization doesn't catch it. The server-side sanitization logic has been updated to sanitize against this attack. This vulnerability is fixed in 5.3.23.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-rhx4-hvx9-j387

10 месяцев назад

Silverstripe Framework has a XSS vulnerability in HTML editor

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-30148

Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to edit content in the CMS could send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The payload would be sanitized on the client-side, but server-side sanitization doesn't catch it. The server-side sanitization logic has been updated to sanitize against this attack. This vulnerability is fixed in 5.3.23.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-rhx4-hvx9-j387

Silverstripe Framework has a XSS vulnerability in HTML editor

CVSS3: 5.4
0%
Низкий
10 месяцев назад

Уязвимостей на страницу