VDB
Sign up
MEDIUM6.1

GHSA-38h6-gmr2-j4wx

Silverstripe Form Capture vulnerable to stored cross-site-scripting

Quick fix

GHSA-38h6-gmr2-j4wx — bigfork/silverstripe-form-capture: upgrade to the fixed version with the command below.

composer require bigfork/silverstripe-form-capture:^3.1.1

Details

### Impact Improper escaping when presenting stored form submissions allowed for an attacker to perform a Cross-Site Scripting attack

### Patches The vulnerability was initially patched in version 1.0.2, and version 1.1.0 includes this patch. The bug was then accidentally re-introduced during a merge error, and has been re-patched in versions 2.2.5 and 3.1.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/bigfork/silverstripe-form-capture
Introduced in: 3.0.0Fixed in: 3.1.1
Fixcomposer require bigfork/silverstripe-form-capture:^3.1.1
Packagist/andrewhaine/silverstripe-form-capture
Introduced in: 0.2.0Fixed in: 1.0.2
Fixcomposer require andrewhaine/silverstripe-form-capture:^1.0.2
Packagist/andrewhaine/silverstripe-form-capture
Introduced in: 2.0.0Fixed in: 2.2.5
Fixcomposer require andrewhaine/silverstripe-form-capture:^2.2.5
Packagist/andrewhaine/silverstripe-form-capture
Introduced in: 1.0.0Fixed in: 1.0.2
Fixcomposer require andrewhaine/silverstripe-form-capture:^1.0.2

References