Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-9cx2-hj6m-fv58: XSS in shortcodes

A malicious content author could add arbitrary attributes to HTML editor shortcodes which could be used to inject a JavaScript payload on the front end of the site. The shortcode providers that ship with Silverstripe CMS have been reviewed and attribute whitelists have been implemented where appropriate to negate this risk.

ghsa
#xss#java#auth

Package

composer silverstripe/assets (Composer)

Affected versions

>= 1.0.0, < 1.11.1

composer silverstripe/framework (Composer)

ghsa: Latest News

GHSA-mj5r-x73q-fjw6: SPEmailHandler-PHP has Potential Abuse for Sending Arbitrary Emails