VDB
Sign up
LOW3.8

GHSA-779c-7w4p-2c4g

Silverstripe admin XSS Vulnerability via WYSIWYG editor

Quick fix

GHSA-779c-7w4p-2c4g — silverstripe/admin: upgrade to the fixed version with the command below.

composer require silverstripe/admin:^1.0.4

Details

It is possible for a bad actor with access to the CMS to make use of onmouseover or onmouseout attributes in the WYSIWYG editor to embed malicious javascript.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/silverstripe/admin
Introduced in: 1.0.3Fixed in: 1.0.4
Fixcomposer require silverstripe/admin:^1.0.4
Packagist/silverstripe/admin
Introduced in: 1.1.0Fixed in: 1.1.1
Fixcomposer require silverstripe/admin:^1.1.1

References