Silverstripe admin XSS Vulnerability via WYSIWYG editor
Low severity
GitHub Reviewed
Published
May 22, 2024
to the GitHub Advisory Database
•
Updated May 22, 2024
Package
Affected versions
>= 1.0.3, < 1.0.4
>= 1.1.0, < 1.1.1
Patched versions
1.0.4
1.1.1
Description
Published to the GitHub Advisory Database
May 22, 2024
Reviewed
May 22, 2024
Last updated
May 22, 2024
It is possible for a bad actor with access to the CMS to make use of onmouseover or onmouseout attributes in the WYSIWYG editor to embed malicious javascript.
References