VDB
MEDIUM 5.4

GHSA-gvrw-qqp5-jgc5

Silverstripe Framework: Possible XSS attack through media embed

Quick fix

GHSA-gvrw-qqp5-jgc5 — silverstripe/framework: upgrade to the fixed version with the command below.

composer require silverstripe/framework:^6.2.2

Details

### Impact The "Insert media from web" functionality in the CMS is vulnerable to XSS from a specially crafted embed.

### Reported by Jack Wallace from Bastion Security

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist / silverstripe/framework
Introduced in: 0 Fixed in: 6.2.2
Fix composer require silverstripe/framework:^6.2.2

References