Reflected cross-site scripting (XSS) In silverstripe/framework
Description
Silverstripe XSS in dev/build returnURL Parameter A XSS risk exists in the returnURL parameter passed to dev/build. An unvalidated url could cause the user to redirect to an unverified third party url outside of the site.
This issue is resolved in framework 3.1.14 stable release.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 3.1.14 |
Aliases
1.
References
1. 2. 3.