Stored XSS Vulnerability in SilverStripe Framework
CVE-2022-28803

5.4MEDIUM

Key Information:

Vendor
CVE Published:
29 June 2022

What is CVE-2022-28803?

The SilverStripe Framework, up until April 7, 2022, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This issue arises when users are able to inject malicious JavaScript link tags via XMLHttpRequest (XHR), potentially allowing attackers to execute harmful scripts in the context of the victim's browser. This vulnerability can lead to unauthorized access to sensitive information, session hijacking, and further exploitation of the web application.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.