VDB
Sign up
MEDIUM6.1

GHSA-rfvw-5848-gxc5

Silverstripe Flash Clipboard Reflected XSS

Quick fix

GHSA-rfvw-5848-gxc5 — silverstripe/framework: upgrade to the fixed version with the command below.

composer require silverstripe/framework:^4.3.5

Details

SilverStripe versions 3.0.0 until 4.3.5 and 4.4.4 are vulnerable to Flash Clipboard Reflected XSS. Versions 4.3.5 and 4.4.4 of `silverstripe/framework` and version 1.3.5 of `silverstripe/admin` contain a fix for this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/silverstripe/framework
Introduced in: 3.0.0Fixed in: 4.3.5
Fixcomposer require silverstripe/framework:^4.3.5
Packagist/silverstripe/admin
Introduced in: 0Fixed in: 1.3.5
Fixcomposer require silverstripe/admin:^1.3.5
Packagist/silverstripe/framework
Introduced in: 4.4.0-rc1Fixed in: 4.4.4
Fixcomposer require silverstripe/framework:^4.4.4

References