MEDIUM6.1
GHSA-gvc8-xjfp-6569
Silverstripe CMS XSS Vulnerability
Quick fix
GHSA-gvc8-xjfp-6569 — silverstripe/cms: upgrade to the fixed version with the command below.
composer require silverstripe/cms:^3.1.16Details
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework before 3.1.16 and 3.2.0 before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Locale or (2) FailedLoginCount parameter to `admin/security/EditForm/field/Members/item/new/ItemEditForm`.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/silverstripe/cms
Introduced in:
0Fixed in: 3.1.16Fix
composer require silverstripe/cms:^3.1.16Packagist/silverstripe/cms
Introduced in:
3.2.0Fixed in: 3.2.1Fix
composer require silverstripe/cms:^3.2.1References
- https://nvd.nist.gov/vuln/detail/CVE-2015-8606[ADVISORY]
- https://cybersecurityworks.com/zerodays/cve-2015-8606-silverstripe.html[WEB]
- https://github.com/silverstripe/silverstripe-cms[PACKAGE]
- http://seclists.org/fulldisclosure/2015/Dec/55[WEB]
- http://www.openwall.com/lists/oss-security/2015/12/17/1[WEB]
- http://www.openwall.com/lists/oss-security/2015/12/17/11[WEB]
- http://www.openwall.com/lists/oss-security/2015/12/18/5[WEB]
- http://www.silverstripe.org/download/security-releases/ss-2015-026[WEB]