Server side cross-site scripting In silverstripe/framework
Description
Silverstripe Framework has a Cross-site Scripting vulnerability with encoded payload
Impact
A bad actor with access to edit content in the CMS could send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The payload would be sanitised on the client-side, but server-side sanitisation doesn't catch it.
The server-side sanitisation logic has been updated to sanitise against this type of attack.
References
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 5.2.16 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4.