logo

CVE-2022-38724 silverstripe/assets

Package

Manager: composer
Name: silverstripe/assets
Vulnerable Version: >=1.0.0 <1.11.1

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

EPSS: 0.00323 pctl0.54779

Details

Silverstripe XSS in shortcodes A malicious content author could add arbitrary attributes to HTML editor shortcodes which could be used to inject a JavaScript payload on the front end of the site. The shortcode providers that ship with Silverstripe CMS have been reviewed and attribute whitelists have been implemented where appropriate to negate this risk.

Metadata

Created: 2022-11-21T23:58:20Z
Modified: 2025-04-29T13:14:57Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-9cx2-hj6m-fv58/GHSA-9cx2-hj6m-fv58.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-9cx2-hj6m-fv58
Finding: F425
Auto approve: 1