VDB
Sign up
MEDIUM5.4

GHSA-pp74-g2q5-j4jf

Silverstipe CMS Stored XSS in custom meta tags

Quick fix

GHSA-pp74-g2q5-j4jf — silverstripe/cms: upgrade to the fixed version with the command below.

composer require silverstripe/cms:^4.11.3

Details

A malicious content author could create a custom meta tag and execute an arbitrary JavaScript payload. This would require convincing a legitimate user to access a page and enter a custom keyboard shortcut. This requires CMS access to exploit.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/silverstripe/cms
Introduced in: 4.0.0Fixed in: 4.11.3
Fixcomposer require silverstripe/cms:^4.11.3

References