CVE-2020-9311

MEDIUM5.4EPSS 0.34%

Silverstripe CMS XSS Vulnerability

發布日:2022/5/24修改日:2024/2/17
也稱為:GHSA-2pw2-qpcp-m47xBIT-silverstripe-2020-9311

描述

In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

參考連結(5)