Stored XSS Vulnerability in SilverStripe Framework
CVE-2022-28803
5.4MEDIUM
What is CVE-2022-28803?
The SilverStripe Framework, up until April 7, 2022, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This issue arises when users are able to inject malicious JavaScript link tags via XMLHttpRequest (XHR), potentially allowing attackers to execute harmful scripts in the context of the victim's browser. This vulnerability can lead to unauthorized access to sensitive information, session hijacking, and further exploitation of the web application.
