LOW3.8
GHSA-779c-7w4p-2c4g
Silverstripe admin XSS Vulnerability via WYSIWYG editor
Quick fix
GHSA-779c-7w4p-2c4g — silverstripe/admin: upgrade to the fixed version with the command below.
composer require silverstripe/admin:^1.0.4Details
It is possible for a bad actor with access to the CMS to make use of onmouseover or onmouseout attributes in the WYSIWYG editor to embed malicious javascript.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/silverstripe/admin
Introduced in:
1.0.3Fixed in: 1.0.4Fix
composer require silverstripe/admin:^1.0.4Packagist/silverstripe/admin
Introduced in:
1.1.0Fixed in: 1.1.1Fix
composer require silverstripe/admin:^1.1.1