MEDIUM5.4
GHSA-vv3r-fxqp-vr3f
XSS via uploaded gpx file
Quick fix
GHSA-vv3r-fxqp-vr3f — silverstripe/assets: upgrade to the fixed version with the command below.
composer require silverstripe/assets:^1.11.1Details
A malicious content author could upload a GPX file with a Javascript payload. The payload could then be executed by luring a legitimate user to view the file in a browser with support for GPX files. GPX is an XML-based format used to store GPS data.
By default, Silverstripe CMS will no longer allow GPX files to be uploaded to the assets area.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/silverstripe/assets
Introduced in:
1.0.0Fixed in: 1.11.1Fix
composer require silverstripe/assets:^1.11.1References
- https://nvd.nist.gov/vuln/detail/CVE-2022-38147[ADVISORY]
- https://forum.silverstripe.org/c/releases[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/assets/CVE-2022-38147.yaml[WEB]
- https://www.silverstripe.org/blog/tag/release[WEB]
- https://www.silverstripe.org/download/security-releases[WEB]
- https://www.silverstripe.org/download/security-releases/cve-2022-38147[WEB]