Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-rppc-655v-7j3c: Stored XSS in link tags added via XHR in SilverStripe Framework

SilverStripe Framework 4.x prior to 4.10.9 is vulnerable to cross-site scripting inside the href attribute of an HTML hyperlink, which can be added to website content via XMLHttpRequest (XHR) by an authenticated CMS user.

ghsa
#xss#web#git#perl#auth

Stored XSS in link tags added via XHR in SilverStripe Framework

Moderate severity GitHub Reviewed Published Jun 29, 2022 • Updated Jun 29, 2022

Related news

CVE-2022-28803: Silverstripe CMS » the open source CMS that empowers great web teams

In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR).