CVE-2022-38724
MEDIUM5.4EPSS 0.32%Silverstripe XSS in shortcodes
發布日:2022/11/21修改日:2025/4/29
描述
A malicious content author could add arbitrary attributes to HTML editor shortcodes which could be used to inject a JavaScript payload on the front end of the site. The shortcode providers that ship with Silverstripe CMS have been reviewed and attribute whitelists have been implemented where appropriate to negate this risk.
受影響套件(2)
- Packagist/silverstripe/assets>= 1.0.0, < 1.11.1
- Packagist/silverstripe/framework>= 4.0.0, < 4.11.13
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-38724
- WEBhttps://forum.silverstripe.org/c/releases
- WEBhttps://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/assets/CVE-2022-38724.yaml
- WEBhttps://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/CVE-2022-38724.yaml
- WEBhttps://www.silverstripe.org/blog/tag/release
- WEBhttps://www.silverstripe.org/download/security-releases
- WEBhttps://www.silverstripe.org/download/security-releases/cve-2022-38724