QID 994809
Date Published: 2023-08-14
QID 994809: PHP (Composer) Security Update for silverstripe/cms (GHSA-xmjh-wjc5-wg4h)
There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-xmjh-wjc5-wg4h for updates and patch information.
Vendor References
- GHSA-xmjh-wjc5-wg4h -
github.com/advisories/GHSA-xmjh-wjc5-wg4h
CVEs related to QID 994809
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xmjh-wjc5-wg4h | silverstripe/cms |
|