VDB
Sign up
MEDIUM6.1

GHSA-xmjh-wjc5-wg4h

Silverstripe CMS XSS Vulnerability

Quick fix

GHSA-xmjh-wjc5-wg4h — silverstripe/cms: upgrade to the fixed version with the command below.

composer require silverstripe/cms:^3.4.4

Details

There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/silverstripe/cms
Introduced in: 0Fixed in: 3.4.4
Fixcomposer require silverstripe/cms:^3.4.4
Packagist/silverstripe/cms
Introduced in: 3.5.0Fixed in: 3.5.2
Fixcomposer require silverstripe/cms:^3.5.2

References