VDB
Sign up
MEDIUM5.4

GHSA-9cx2-hj6m-fv58

Silverstripe XSS in shortcodes

Quick fix

GHSA-9cx2-hj6m-fv58 — silverstripe/assets: upgrade to the fixed version with the command below.

composer require silverstripe/assets:^1.11.1

Details

A malicious content author could add arbitrary attributes to HTML editor shortcodes which could be used to inject a JavaScript payload on the front end of the site. The shortcode providers that ship with Silverstripe CMS have been reviewed and attribute whitelists have been implemented where appropriate to negate this risk.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/silverstripe/assets
Introduced in: 1.0.0Fixed in: 1.11.1
Fixcomposer require silverstripe/assets:^1.11.1
Packagist/silverstripe/framework
Introduced in: 4.0.0Fixed in: 4.11.13
Fixcomposer require silverstripe/framework:^4.11.13

References