CVE-2020-25817
Summary
| CVE | CVE-2020-25817 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-08 18:15:00 UTC |
| Updated | 2021-06-17 15:47:00 UTC |
| Description | SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for purposes involving external or user submitted data in custom project code, it can lead to vulnerabilities such as XSS on HTML output rendered through this custom code. This is now mitigated by disabling external entities during parsing. (The correct CVE ID year is 2020 [CVE-2020-25817, not CVE-2021-25817]). |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Silverstripe | Silverstripe | All | All | All | All |
| Application | Silverstripe | Silverstripe | 4.6.0 | rc1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Releases » Silverstripe CMS | CONFIRM | www.silverstripe.org | |
| CVE-2021-25817 XXE Vulnerability in CSSContentParser » Silverstripe CMS | MISC | www.silverstripe.org | |
| Page not found » Silverstripe CMS | MISC | www.silverstripe.org | |
| Latest Releases topics - Silverstripe Forum | MISC | forum.silverstripe.org | |
| Blog - Tagged with release » Silverstripe CMS | MISC | www.silverstripe.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.