MEDIUM5.4
GHSA-2pw2-qpcp-m47x
Silverstripe CMS XSS Vulnerability
Quick fix
GHSA-2pw2-qpcp-m47x — silverstripe/framework: upgrade to the fixed version with the command below.
composer require silverstripe/framework:^3.7.5Details
In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/silverstripe/cms
Introduced in:
0No fixed version published yet for silverstripe/cms (composer). Pin to a known-safe version or switch to an alternative.
Packagist/silverstripe/framework
Introduced in:
3.0.0Fixed in: 3.7.5Fix
composer require silverstripe/framework:^3.7.5References
- https://nvd.nist.gov/vuln/detail/CVE-2020-9311[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/CVE-2020-9311.yaml[WEB]
- https://github.com/silverstripe/silverstripe-cms[PACKAGE]
- https://www.silverstripe.org/download/security-releases/CVE-2020-9311[WEB]
- https://www.silverstripe.org/download/security-releases/cve-2020-9311[WEB]