Server side cross-site scripting In silverstripe/cms
Description
Silverstripe CMS XSS Vulnerability In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 3.7.5 | ||
packagist | 4.5.1 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.