Cross-Site Scripting Vulnerability in Silverstripe Framework by Silverstripe
CVE-2022-25238

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
28 June 2022

What is CVE-2022-25238?

The Silverstripe framework is susceptible to Cross-Site Scripting (XSS) attacks, allowing authenticated CMS users to introduce malicious scripts into website content via XHR requests. This vulnerability arises when the cwp-core module is not installed and the sanitise_server_side configuration is disabled in the project code, permitting unfiltered data to be rendered in the browser. Proper security measures, such as enabling the necessary modules and configurations, should be implemented to mitigate this risk.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.