MEDIUM6.1
GHSA-j66h-cc96-c32q
Cross-site Scripting in SilverStripe Framework
Quick fix
GHSA-j66h-cc96-c32q — silverstripe/admin: upgrade to the fixed version with the command below.
composer require silverstripe/admin:^1.8.1Details
SilverStripe Framework through 4.8.1 allows XSS.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/silverstripe/admin
Introduced in:
1.0.0Fixed in: 1.8.1Fix
composer require silverstripe/admin:^1.8.1References
- https://nvd.nist.gov/vuln/detail/CVE-2021-36150[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/admin/CVE-2021-36150.yaml[WEB]
- https://github.com/silverstripe/silverstripe-framework[PACKAGE]
- https://github.com/silverstripe/silverstripe-framework/releases[WEB]
- https://www.silverstripe.org/download/security-releases/CVE-2021-36150[WEB]