Headline
GHSA-rppc-655v-7j3c: Stored XSS in link tags added via XHR in SilverStripe Framework
SilverStripe Framework 4.x prior to 4.10.9 is vulnerable to cross-site scripting inside the href attribute of an HTML hyperlink, which can be added to website content via XMLHttpRequest (XHR) by an authenticated CMS user.
Stored XSS in link tags added via XHR in SilverStripe Framework
Moderate severity GitHub Reviewed Published Jun 29, 2022 • Updated Jun 29, 2022
Related news
CVE-2022-28803: Silverstripe CMS » the open source CMS that empowers great web teams
In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR).