VDB
Sign up
MEDIUM6.1

GHSA-gvc8-xjfp-6569

Silverstripe CMS XSS Vulnerability

Quick fix

GHSA-gvc8-xjfp-6569 — silverstripe/cms: upgrade to the fixed version with the command below.

composer require silverstripe/cms:^3.1.16

Details

Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework before 3.1.16 and 3.2.0 before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Locale or (2) FailedLoginCount parameter to `admin/security/EditForm/field/Members/item/new/ItemEditForm`.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/silverstripe/cms
Introduced in: 0Fixed in: 3.1.16
Fixcomposer require silverstripe/cms:^3.1.16
Packagist/silverstripe/cms
Introduced in: 3.2.0Fixed in: 3.2.1
Fixcomposer require silverstripe/cms:^3.2.1

References