logo

Database

Server side cross-site scripting In silverstripe/framework

Description

Silverstripe XSS In GridField print A cross-site scripting vulnerability has been discovered in the print view of GridField.

This vulnerability can only be exploited if a user with CMS access has posted malicious or unescaped HTML into any field of an object in a GridField, and the print feature is used.

This has been resolved by ensuring that the print feature safely escapes all fields.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions