MEDIUM6.1
GHSA-xmjh-wjc5-wg4h
Silverstripe CMS XSS Vulnerability
Quick fix
GHSA-xmjh-wjc5-wg4h — silverstripe/cms: upgrade to the fixed version with the command below.
composer require silverstripe/cms:^3.4.4Details
There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/silverstripe/cms
Introduced in:
0Fixed in: 3.4.4Fix
composer require silverstripe/cms:^3.4.4Packagist/silverstripe/cms
Introduced in:
3.5.0Fixed in: 3.5.2Fix
composer require silverstripe/cms:^3.5.2