MEDIUM5.4
GHSA-pp74-g2q5-j4jf
Silverstipe CMS Stored XSS in custom meta tags
Quick fix
GHSA-pp74-g2q5-j4jf — silverstripe/cms: upgrade to the fixed version with the command below.
composer require silverstripe/cms:^4.11.3Details
A malicious content author could create a custom meta tag and execute an arbitrary JavaScript payload. This would require convincing a legitimate user to access a page and enter a custom keyboard shortcut. This requires CMS access to exploit.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/silverstripe/cms
Introduced in:
4.0.0Fixed in: 4.11.3Fix
composer require silverstripe/cms:^4.11.3References
- https://nvd.nist.gov/vuln/detail/CVE-2022-37421[ADVISORY]
- https://forum.silverstripe.org/c/releases[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/cms/CVE-2022-37421.yaml[WEB]
- https://www.silverstripe.org/blog/tag/release[WEB]
- https://www.silverstripe.org/download/security-releases[WEB]
- https://www.silverstripe.org/download/security-releases/cve-2022-37421[WEB]