VDB
Sign up
MEDIUM5.4

GHSA-2pw2-qpcp-m47x

Silverstripe CMS XSS Vulnerability

Quick fix

GHSA-2pw2-qpcp-m47x — silverstripe/framework: upgrade to the fixed version with the command below.

composer require silverstripe/framework:^3.7.5

Details

In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/silverstripe/cms
Introduced in: 0

No fixed version published yet for silverstripe/cms (composer). Pin to a known-safe version or switch to an alternative.

Packagist/silverstripe/framework
Introduced in: 3.0.0Fixed in: 3.7.5
Fixcomposer require silverstripe/framework:^3.7.5

References