CVE-2020-9311

MEDIUM5.4EPSS 0.34%

Silverstripe CMS XSS Vulnerability

Published: 5/24/2022Modified: 2/17/2024
Also known as:GHSA-2pw2-qpcp-m47xBIT-silverstripe-2020-9311

Description

In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References (5)